Why is not happening now? Inference is still expensive and local models are not there yet, so there's no ROI in making this at scale. But once inference is local and cheap as electricity or running water, this is the natural development. How do we stop the spreading then?
Are there already some documented experiments?
That is a hefty set of assumptions you are making there. There is no guarantee such a reality will ever exist, and decent odds against it.
At the same time, if you consider it to be a virus or malware when an LLM generates and runs code that harms a product or device... we are already there. Agentic AI with too much system access is already a thing. Just look at the anecdotes of "My AI deleted by database!" and other such stories.