Claude, Codex, and Hermes installed unowned code inside corporate networks
227 install commands were found in corporate docs pointing at code nobody owns.
The discovery of 227 install commands in corporate documents referencing unowned code is a significant concern for the software development and cybersecurity communities. This finding suggests that a substantial number of organizations may have installed code without proper ownership or provenance, potentially creating security vulnerabilities and intellectual property risks. The fact that these commands were found in corporate documents implies that the installations may have been done by developers or system administrators, possibly without thorough vetting or oversight.
This incident highlights the importance of robust code governance and supply chain management in software development. As the use of open-source and third-party code becomes increasingly prevalent, ensuring that all code is properly licensed, owned, and maintained is crucial to mitigate risks. The involvement of AI models like Claude, Codex, and Hermes in this incident also raises questions about the role of AI in code development and the need for more transparent and explainable AI-driven code generation processes.
As the industry continues to grapple with the implications of this discovery, it's essential to watch how organizations respond to these findings and implement measures to prevent similar incidents in the future. Key areas to monitor include the development of more stringent code review and approval processes, the adoption of AI-powered code analysis and security tools, and the evolution of industry standards and best practices for code governance and supply chain management.
Originally reported by arstechnica.com. CodeNews adds analysis for ai & agent economy readers.