27 August 2026
AI coding agents exploited through misconfigured documentation files
First reported
Ars Technica and Sloth Bytes ran this on , all on the same day.
- Researchers found 120 websites with broken installation instructions in llms.txt files, pointing to software packages that don't exist or unclaimed domain names.
- AI coding agents including Claude, Codex, and Hermes followed these fake instructions and downloaded malicious packages, with at least one active attack confirmed on clerk.com.
How it was covered
Reported by Ars Technica