Intelligence
AEV-2026-0040

Clerk's own genuine documentation pointed agents at a package a third party had registered and filled with malware (MAL-2026-11069)

Clerk's own genuine agent facing documentation instructed agents to run clerk-next-fix-auth-protection. Run bare through npx without Clerk's own scoped eslint plugin package already installed, that name resolved on the public npm registry to a package an unrelated third party had registered, at versions 7.7.7 and 8.8.8, carrying an install hook that transmitted the installing machine's username, hostname, working directory and a timestamp to an external server. Cataloged as MAL-2026-11069 under CWE-506. Clerk's own security team corrected the documentation after disclosure.

AESS 7.2 highConfirmedStatus: publishedExecution AuthorityAgent Identity

Affected

Organisation
Clerk
Product
clerk-next-fix-auth-protection, an unofficial npm package, not published by Clerk
Component
The bare, unscoped command name referenced by Clerk's own agent facing documentation, resolved through npx with Clerk's own scoped eslint plugin package not already installed
Versions
7.7.7 and 8.8.8, per independently reported analysis; unknown whether other versions existed
Configurations
npx invoked against the bare command name without Clerk's own scoped @clerk/eslint-plugin package already installed locally

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
Follow Clerk's own genuine agent facing documentation to run a named auth protection fix command
Agent
unknown
Delegating actor
unknown
Action
Resolved and executed a package a third party, not Clerk, had registered under the bare command name Clerk's own documentation referenced, running its install hook
Target resource
The installing machine's own local environment and network egress
Environment
Wherever a developer or agent followed Clerk's own documentation and ran the named command through npx
Credentials used
unknown
Privileges available
Ordinary local install time privileges of whichever account ran npx
Authority presented
Clerk's own genuine, currently corrected documentation instructing the named command by reference
Authority required
Confirmation that the resolved package was published by Clerk, or by a party Clerk authorized, before executing its install hook
Applicable policy
unknown
Approval mechanism
none
Required approver
unknown
Independent approval
no
Action binding
Clerk's own instruction authorized running a named auth protection command; nothing bound that authorization to the specific, unaffiliated package identity npm actually resolved
Sequence context
unknown

Impact

Consequence
degraded
Reach
unknown
Reversibility
irreversible
Detectability
delayed
Propagation
unknown
Recovery
Clerk's own security team is reported to have corrected the documentation after disclosure; this record's own verified copy of clerk.com/llms.txt and clerk.com/docs/llms-full.txt reflects genuine, currently published guidance. Whether the malicious package itself was removed, quarantined or remains resolvable on the npm registry, and how many installations it received before or after the correction, are not established by material available to this session.

Evidence

Primary sources

Supporting sources

Reproduction status
Reported by Hertz's own research and independently reported secondary coverage as a real, already registered malicious package found during the research's own reading of production llms.txt files, distinct from the researchers' own controlled, inert PoC packages. This session could not directly fetch osv.dev, npmjs.com or the underlying malware record and relies on corroboration across multiple independently phrased web search passes.
Evidence state
Confirmed

Known unknowns

  • Whether the malicious package remains live, has been removed, or is quarantined on the npm registry as of this entry's own publication.
  • How many installations the malicious package received, before or after Clerk's own documentation correction.
  • Whether install of the malicious package occurred through an autonomous coding agent, a human developer following the documentation directly, or both, since the reporting this entry relies on does not distinguish the two for this specific occurrence.
  • The exact date the malicious package was first published, and the exact date of Clerk's own documentation correction.

Limitations

  • Direct fetch of osv.dev, the primary malware record, was blocked by this session's network egress policy. The identifier MAL-2026-11069, the CWE-506 classification, the reported versions 7.7.7 and 8.8.8 and the reported install hook behavior are corroborated across multiple independently phrased web search passes rather than read directly from OSV's own record, and this entry's evidenceState of confirmed rests on that corroboration plus Clerk's own reported acknowledgement and documentation correction rather than on a direct read of the primary malware record.
  • Direct fetch of clerk.com was not confirmed reachable from this session; the current wording of Clerk's own llms.txt and llms.full.txt pages, as distinct from the wording reported to have been corrected, was not independently read by this session.

Claim provenance