
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
generate llms.txt–using your sitemap.xml.
$ npx llmstxt gen https://dotenvx.com/sitemap.xml
$ npx llmstxt gen https://dotenvx.com/sitemap.xml
- [dotenvx run -f](https://dotenvx.com/docs/advanced/run-f.html): Compose multiple .env files for environment variables loading, as you need.
- [dotenvx run --log-level](https://dotenvx.com/docs/advanced/run-log-level.html): Set `--log-level` to whatever you wish.
- [dotenvx run --env HELLO=String](https://dotenvx.com/docs/advanced/run-overload.html): Override existing env variables. These can be variables already on your machine or variables loaded as files consecutively. The last variable seen will 'win'.
- [dotenvx run --quiet](https://dotenvx.com/docs/advanced/run-quiet.html): Use `--quiet` to suppress all output (except errors).
- [dotenvx run - Shell Expansion](https://dotenvx.com/docs/advanced/run-shell-expansion.html): Prevent your shell from expanding inline `$VARIABLES` before dotenvx has a chance to inject them. Use a subshell.
...
Basic usage
Outputs to stdout.
$ llmstxt gen https://dotenvx.com/sitemap.xml
- [dotenvx run -f](https://dotenvx.com/docs/advanced/run-f.html): Compose multiple .env files for environment variables loading, as you need.
- [dotenvx run --log-level](https://dotenvx.com/docs/advanced/run-log-level.html): Set `--log-level` to whatever you wish.
- [dotenvx run --quiet](https://dotenvx.com/docs/advanced/run-quiet.html): Use `--quiet` to suppress all output (except errors).
...
Write to file.
$ llmstxt gen https://dotenvx.com/sitemap.xml > llms.txt
Advanced options
Exclude paths from generation.
# exclude all blog posts
$ llmstxt gen https://dotenvx.com/sitemap.xml --exclude-path "**/blog/**"
# exclude all docs
$ llmstxt gen https://dotenvx.com/sitemap.xml --exclude-path "**/docs/**"
# exclude privacy and terms
$ llmstxt gen https://dotenvx.com/sitemap.xml -ep "**/privacy**" -ep "**/terms**"
Include paths for generation.
# include all docs only
$ llmstxt gen https://dotenvx.com/sitemap.xml --include-path "**/docs/**"
# include all blogs only
$ llmstxt gen https://dotenvx.com/sitemap.xml -ip "**/blog/**"
Use --replace-title to remove redundant text from your page titles. For example, dotenvx's titles all end with | dotenvx. I want to replace those with empty string.
$ llmstxt gen https://dotenvx.com/sitemap.xml --replace-title 's/\| dotenvx//'
Set your website's heading 1 title.
$ llmstxt gen https://dotenvx.com/sitemap.xml --title 'dotenvx'
Set your website's description.
$ llmstxt gen https://dotenvx.com/sitemap.xml --description 'This is a description'
I'm using it to generate dotenvx.com/llms.txt with the following command:
npx llmstxt gen https://dotenvx.com/sitemap.xml -ep "**/privacy**" -ep "**/terms**" -ep "**/blog/**" -ep "**/stats/**" -ep "**/support/**" -rt 's/\| dotenvx//' -t 'dotenvx' > llms.txt
FAQs
convert `sitemap.xml` to `llms.txt`
The npm package llmstxt receives a total of 91 weekly downloads. As such, llmstxt popularity was classified as not popular.
We found that llmstxt demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.