Critical Flaw: llms.txt Files Trick Claude and Other Agents into Installing Malware
Ars Technica AI · rss · 2026-08-27
Researchers discovered a new attack vector using llms.txt and llms-full.txt files to trick AI coding agents into automatically executing malicious code.
Details:
- Scans revealed over 100 sites referencing unclaimed packages or domains in their documentation files.
- By registering these names and hosting beacons, researchers received callbacks from a Fortune 500 company within an hour, followed by dozens more.
- Process chain analysis identified coding agents including Claude, OpenAI's Codex, and Nous Research's Hermes as the culprits.
- The exploit leverages an emerging standard for machine-readable site summaries (similar to robots.txt).
More from coding & agent
- Remotion Studio implements WebMCP for contextual agent actions — Vjeux · 2026-08-27
- What Do Agents Do When They Hit a Raw Table Nobody Has Mapped? No Shared Keys — No-Plant-5234 · 2026-08-27
- PwC: Enterprises Should Standardize Agent Architecture, Not Rebuild — rohanpaul_ai · 2026-08-27
- Paper warns multilingual LLM agent teams hit a "Tower of Babel" coordination breakdown — anas_ant · 2026-08-27
- NoSpoon Music Video Agent Alpha: Autonomous Video Generation — Kyrannio · 2026-08-27
- Best Buy engineer dissects the Agentic Commerce stack — AI Engineer · 2026-08-27