PulseAugur
实时 09:19:05
English(EN) Researcher Tricked Claude, Codex and Hermes into Running Malware

AI 编码代理被诱骗通过未认领的软件包运行恶意软件

研究人员发现了一个安全漏洞,AI 编码代理可以通过引用公共文档中未认领的软件包被诱骗执行恶意软件。通过注册公司 `llms.txt` 文件中列出但未被拥有的软件包名称,攻击者可以部署恶意代码,然后由 AI 代理执行。此漏洞已在包括 AnthropicClaudeOpenAICodexNous ResearchHermes 在内的 AI 模型上得到演示,突显了 AI 与公共代码注册表交互的信任模型中存在严重缺陷。 AI

影响 凸显了 AI 编码代理中的一个关键安全漏洞,可能影响企业采用和对 AI 驱动的开发工作流程的信任。

排序理由 在 AI 编码代理中发现安全漏洞,而非新的模型发布或核心研究论文。

在 HN — claude cli stories 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

AI 编码代理被诱骗通过未认领的软件包运行恶意软件

本文如何被排名

Signal score
48 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
在 AI 编码代理中发现安全漏洞,而非新的模型发布或核心研究论文。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. HN — claude cli stories TIER_1 English(EN) · CuriousLLM ·

    研究人员诱骗 Claude、Codex 和 Hermes 运行恶意软件