Наталя ХандусенкоAI Eng
31 August 2026, 16:29
2026-08-31
AI agents download malware by reading official llms.txt files on leading companies' websites
Cybersecurity researchers have discovered a new attack vector: autonomous AI agents execute instructions from official llms.txt files hosted on the websites of Fortune 500 companies and independently install malware.
Cybersecurity researchers have discovered a new attack vector: autonomous AI agents execute instructions from official llms.txt files hosted on the websites of Fortune 500 companies and independently install malware.
The llms.txt file is a new standard (similar to robots.txt) that companies add to their websites to provide artificial intelligence with a machine-readable short description of the product, API, and instructions for installing the necessary packages. However, due to the carelessness of developers, such files contain hundreds of errors and links to non-existent resources, writes Cybernews.
What is the essence of vulnerability:
AI assistants that help write code or integrate products perceive the contents of llms.txt as absolute instructions. If it says to install a certain package, the AI executes that command without additional checks.
Researchers analyzed over 8,500 llms.txt files and found over 237 non-existent or unregistered packages in PyPI, npm, RubyGems, etc. All hackers need to do is register a package with that name and add malicious code to it.
Israeli security experts registered several such fake packages with minimal code for collecting statistics. Just 4 minutes later, the server of one of the giant Fortune 500 corporations automatically downloaded and executed their code.
In addition, researchers have already recorded a real malicious campaign. For example, the Clerk authentication service file contained an instruction to run the clerk-next-fix-auth-protection command. Since no such official package existed, the hackers registered it themselves, creating a threat to all developers who relied on AI prompts. The company has now fixed this bug.
Experts warn that the line between plain text and executable code has completely disappeared. Any information on a website is now a direct instruction to action for artificial intelligence, which creates a fundamentally new large-scale vector of cyberattacks.
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Нейронні мережі для генерації зображень бачать світ по-своєму, їхню логіку зрозуміти часом зовсім неможливо. Але таки хочеться. На честь Дня Незалежності України редакція dev.ua вирішила провести невеликий експеримент.
Ми задали чотирьом різним нейронним мережам п’ять однакових запитів: «прапор України», «День Незалежності України», «український Крим», «перемога України» та «українці». Отриманими результатами ми ділимося з вами нижче.
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok з’явилася нова функція «Розумний фон». З її допомогою як фон для тіктоків можна підставляти згенеровані нейромережею зображення. Редакція dev.ua протестувала цю технологію і ділиться своїми враженнями.