AEV-2026-0040
Clerk's own genuine documentation pointed agents at a package a third party had registered and filled with malware (MAL-2026-11069)
Clerk's own genuine agent facing documentation instructed agents to run clerk-next-fix-auth-protection. Run bare through npx without Clerk's own scoped eslint plugin package already installed, that name resolved on the public npm registry to a package an unrelated third party had registered, at versions 7.7.7 and 8.8.8, carrying an install hook that transmitted the installing machine's username, hostname, working directory and a timestamp to an external server. Cataloged as MAL-2026-11069 under CWE-506. Clerk's own security team corrected the documentation after disclosure.
Affected
- Organisation
- Clerk
- Product
- clerk-next-fix-auth-protection, an unofficial npm package, not published by Clerk
- Component
- The bare, unscoped command name referenced by Clerk's own agent facing documentation, resolved through npx with Clerk's own scoped eslint plugin package not already installed
- Versions
- 7.7.7 and 8.8.8, per independently reported analysis; unknown whether other versions existed
- Configurations
- npx invoked against the bare command name without Clerk's own scoped @clerk/eslint-plugin package already installed locally
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- Follow Clerk's own genuine agent facing documentation to run a named auth protection fix command
- Agent
- unknown
- Delegating actor
- unknown
- Action
- Resolved and executed a package a third party, not Clerk, had registered under the bare command name Clerk's own documentation referenced, running its install hook
- Target resource
- The installing machine's own local environment and network egress
- Environment
- Wherever a developer or agent followed Clerk's own documentation and ran the named command through npx
- Credentials used
- unknown
- Privileges available
- Ordinary local install time privileges of whichever account ran npx
- Authority presented
- Clerk's own genuine, currently corrected documentation instructing the named command by reference
- Authority required
- Confirmation that the resolved package was published by Clerk, or by a party Clerk authorized, before executing its install hook
- Applicable policy
- unknown
- Approval mechanism
- none
- Required approver
- unknown
- Independent approval
- no
- Action binding
- Clerk's own instruction authorized running a named auth protection command; nothing bound that authorization to the specific, unaffiliated package identity npm actually resolved
- Sequence context
- unknown
Impact
- Consequence
- degraded
- Reach
- unknown
- Reversibility
- irreversible
- Detectability
- delayed
- Propagation
- unknown
- Recovery
- Clerk's own security team is reported to have corrected the documentation after disclosure; this record's own verified copy of clerk.com/llms.txt and clerk.com/docs/llms-full.txt reflects genuine, currently published guidance. Whether the malicious package itself was removed, quarantined or remains resolvable on the npm registry, and how many installations it received before or after the correction, are not established by material available to this session.
Evidence
Primary sources
- MAL-2026-11069 (OSV.dev, Open Source Vulnerabilities)
Supporting sources
- llms.txt files let hackers trick AI agents into malware (Cybernews)
- Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents (Medium)
- llms.txt (Clerk)
- llms-full.txt (Clerk)
- Reproduction status
- Reported by Hertz's own research and independently reported secondary coverage as a real, already registered malicious package found during the research's own reading of production llms.txt files, distinct from the researchers' own controlled, inert PoC packages. This session could not directly fetch osv.dev, npmjs.com or the underlying malware record and relies on corroboration across multiple independently phrased web search passes.
- Evidence state
- Confirmed
Known unknowns
- Whether the malicious package remains live, has been removed, or is quarantined on the npm registry as of this entry's own publication.
- How many installations the malicious package received, before or after Clerk's own documentation correction.
- Whether install of the malicious package occurred through an autonomous coding agent, a human developer following the documentation directly, or both, since the reporting this entry relies on does not distinguish the two for this specific occurrence.
- The exact date the malicious package was first published, and the exact date of Clerk's own documentation correction.
Limitations
- Direct fetch of osv.dev, the primary malware record, was blocked by this session's network egress policy. The identifier MAL-2026-11069, the CWE-506 classification, the reported versions 7.7.7 and 8.8.8 and the reported install hook behavior are corroborated across multiple independently phrased web search passes rather than read directly from OSV's own record, and this entry's evidenceState of confirmed rests on that corroboration plus Clerk's own reported acknowledgement and documentation correction rather than on a direct read of the primary malware record.
- Direct fetch of clerk.com was not confirmed reachable from this session; the current wording of Clerk's own llms.txt and llms.full.txt pages, as distinct from the wording reported to have been corrected, was not independently read by this session.
Claim provenance
- independent-reporting
Direct fetch of osv.dev was blocked in this session. The malware identifier, its CWE-506 classification and its association with clerk-next-fix-auth-protection are corroborated across repeated, independently phrased web search passes rather than read directly from OSV's own record.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else. - independent-reporting
Direct fetch of cybernews.com was blocked in this session. Used as corroboration for the reported version numbers, the install hook's own exfiltrated fields, and Clerk's own reported response and documentation correction.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else. - independent-reporting
These URLs were independently returned by repeated web search passes as Clerk's own currently published llms.txt and llms.full.txt destinations. Direct fetch was not confirmed reachable from this session, so this entry does not assert what the pages currently say beyond that they exist and are Clerk's own.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else.
