SecurityEnterpriseTools

Claude, Codex, and Hermes installed unowned code inside corporate networks

Source: Ars Technica · Dan Goodin

Intel Summary

Security reporting indicates that coding models including Claude, Codex, and Hermes have generated package installation commands referencing unowned software code inside corporate documentation. An analysis identified 227 install commands pointing to unregistered package names. This hallucination phenomenon creates software supply chain risks where threat actors can register the vacant package names on public registries, enabling potential remote code execution or data theft inside corporate networks.

Why It Matters

AI package hallucination represents a critical software supply chain vulnerability for enterprise software development. When developers or automated AI agents execute AI-suggested install commands without strict package validation, malicious actors can exploit the gap via namespace registration. Organizations must implement dependency scanning, package verification, and private registry guardrails to mitigate risks from automated AI code generation.

Part of an ongoing development

Independent reporting

Claude, Codex, and Hermes generate unowned package installation commands

Security reporting indicates that coding models including Claude, Codex, and Hermes have generated package installation commands referencing unowned software code inside corporate documentation. An analysis identified 227 install commands pointing to unregistered package names. Claims are as reported; this summary makes no determination about accuracy or significance.

Confidence
Moderate confidence
Corroboration
Limited corroboration

Organizations & Entities