[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-ai-agents-fooled-into-running-malware-via-llmstxt-files":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},5984,"ai-agents-fooled-into-running-malware-via-llmstxt-files","AI Agents Fooled Into Running Malware via llms.txt Files","Researchers tricked Fortune 500 AI agents into running malware via bogus links in llms.txt, the README-style files bots use to learn a project.","Security researchers just proved that the file telling AI agents how to install your software can also tell them to install malware instead.\n\nResearchers at Pandex scanned 8,565 llms.txt files - the README-style guides that tell AI agents which packages, domains, and setup commands to use - and found 237 references to software packages that are broken, expired, or up for grabs. They registered a handful of those abandoned names themselves and waited. Four minutes after publishing, an AI agent had already fetched and run their test payload, triggered by nothing more suspicious than a generic prompt asking it to build a project using a vendor's SDK. No prompt injection, no phishing link, no human in the loop - just an agent trusting a text file.\n\nThe gap in compliance rates is the real story here. Pandex reports that newer, more autonomous models it labels as GPT-5 variants followed the bad instructions more than 90 percent of the time, while Claude Opus 4.8 running on medium effort did so only 30 percent of the time. That is not a security feature so much as a side effect of caution, and it suggests agent autonomy and agent gullibility are currently rising together.\n\nThis is the same trick as prompt injection via calendar invites or poisoned MCP packages, just aimed at a file nobody ever reads with human eyes.","[\"ai-security\",\"supply-chain-attacks\",\"llms.txt\",\"ai-agents\"]","2026-09-02T10:20:00.000Z","2026-09-02T10:52:37.172Z","2026-09-02T10:52:49.088Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"publisher-r1","publisher",1,"The article references 'GPT-5 Luna and Sol' as if these are real OpenAI model names, which is not a legitimate model naming scheme and reads as a fabricated\u002Finconsistent detail that needs verification before publishing.","resolved","security",[32,33,34,35],"ai-security","supply-chain-attacks","llms.txt","ai-agents",[37],{"name":38,"url":39},"Tom's Hardware","https:\u002F\u002Fwww.tomshardware.com\u002Ftech-industry\u002Fartificial-intelligence\u002Fresearchers-easily-trick-fortune-500-companies-ai-agents-into-running-arbitrary-code-supply-chain-attack-via-llms-txt-guidance-file-illustrates-how-data-has-become-code",0,{"sections":42},[43,48,52,57,62,67,72,77,82,87,92,97,102,107],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",565,"2026-09-05T00:03:08.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]