Unowned packages reached corporate networks through coding agents' documentation files
Researchers found 227 install commands in 120 machine-readable documentation files pointing to unregistered packages or expired domains; coding agents at several companies executed proof-of-concept packages, and one abandoned package name was already serving malware. A separate letter from at least 100 technology and infrastructure companies asks governments to fund AI-enabled defence for hospitals, water systems and local authorities before attacks become more capable.
Artificial Intelligence··Night
From documentation file to executed command
Researchers scanned 8,265 llms.txt and llms-full.txt files across 6,214 live domains, including defence contractors and large technology companies. They found 227 commands in 120 files pointing to packages unregistered on PyPI or npm, or to expired domains. Files intended to make a website easier for an agent to read had thereby become a surface for installing software.[1]
Malware outside the dependency manifest
The researchers claimed several empty names and placed proof-of-concept packages that made executing machines contact their server; agents ran them within an hour. A separate file on clerk.com pointed through npx to another unowned package name, which someone had claimed to serve live malware. Because npx ran the package from npm's cache, it did not enter the project's dependency manifest. Ars Technica reported that if the agent had already installed a binary included in @clerk/eslint-plugin, there was no threat; if not, the malicious package would be installed. That condition leaves two supported explanations for a particular execution: the legitimate binary may already have been present, or npx may have fetched the malicious namesake. The abandoned name therefore does not by itself establish an infection; Clerk later fixed the file, and whether any actual infection occurred remains unknown.[1]
A joint call to resource defenders
At least 100 AI, cybersecurity and critical-infrastructure companies, including OpenAI, Anthropic, Google and Microsoft, issued a joint appeal to governments. The letter asks for funded cyber-defence programmes, faster threat-intelligence sharing, and access for hospitals, water-treatment plants and local authorities to AI models with specialist security skills. The signatories argue that the window for strengthening defences before attack capabilities spread more widely is narrowing. The documentation-file episode places the execution boundary with agent and software providers; the letter places the provision of defensive tools and resources with governments and critical-infrastructure operators.[1], [2]