Claude, Codex, and Hermes installed unowned code inside corporate networks
Analysis found 227 install commands from Claude, Codex, and Hermes agents inside corporate networks pointing to packages with no verifiable owner.
Researchers found 227 install commands issued by the AI coding agents Claude, Codex, and Hermes inside corporate environments, with the referenced packages having no clear owner. The finding highlights agentic software supply-chain risk, as AI agents can pull unverified third-party code into production networks without organizational oversight. The article is published in Ars Technica's security section and frames this as an emerging governance gap for AI-driven development.
- 227 install commands found in corporate documentation referencing unowned packages
- Agents Claude, Codex, and Hermes implicated in installing unverified dependencies
- Agentic installs create software supply-chain exposure in corporate networks
- Underscores need for governance over agent-initiated package installs
227 install commands were found in corporate docs pointing at code nobody owns.
This source does not provide full text. Read it at arstechnica.com.