
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
generate
llms.txt–using yoursitemap.xml.

$ npx -y llmstxt gen https://vercel.com/sitemap.xml
$ npx -y llmstxt gen https://vercel.com/sitemap.xml
- [Vercel Documentation](https://vercel.com/docs): Vercel's Frontend Cloud gives developers frameworks, workflows, and infrastructure to build a faster, more personalized web
- [Accounts on Vercel](https://vercel.com/docs/accounts): Learn how to manage your Vercel account and team members.
- [Create a Team](https://vercel.com/docs/accounts/create-a-team): Teams on Vercel allow you to collaborate with members on projects, and grant you access to additional resources. Learn how to create or join a team on Vercel.
- [Create an Account](https://vercel.com/docs/accounts/create-an-account): Learn how to create a Hobby team on Vercel and manage your login connections through your dashboard.
- [Manage Emails](https://vercel.com/docs/accounts/manage-emails): Learn how to manage your email addresses on Vercel.
- [Account Plans on Vercel](https://vercel.com/docs/accounts/plans): Learn about the different plans available on Vercel.
- [Vercel Enterprise Plan](https://vercel.com/docs/accounts/plans/enterprise): Learn about the Enterprise plan for Vercel, including features, pricing, and more.
...
Basic usage
Outputs to stdout.
$ llmstxt gen https://vercel.com/sitemap.xml
- [Vercel Documentation](https://vercel.com/docs): Vercel's Frontend Cloud gives developers frameworks, workflows, and infrastructure to build a faster, more personalized web
- [Accounts on Vercel](https://vercel.com/docs/accounts): Learn how to manage your Vercel account and team members.
- [Create a Team](https://vercel.com/docs/accounts/create-a-team): Teams on Vercel allow you to collaborate with members on projects, and grant you access to additional resources. Learn how to create or join a team on Vercel.
- [Create an Account](https://vercel.com/docs/accounts/create-an-account): Learn how to create a Hobby team on Vercel and manage your login connections through your dashboard.
- [Manage Emails](https://vercel.com/docs/accounts/manage-emails): Learn how to manage your email addresses on Vercel.
- [Account Plans on Vercel](https://vercel.com/docs/accounts/plans): Learn about the different plans available on Vercel.
- [Vercel Enterprise Plan](https://vercel.com/docs/accounts/plans/enterprise): Learn about the Enterprise plan for Vercel, including features, pricing, and more.
...
Write to file.
$ llmstxt gen https://vercel.com/sitemap.xml > llms.txt
Advanced options
Exclude paths from generation.
# exclude all blog posts
$ llmstxt gen https://vercel.com/sitemap.xml --exclude-path "**/blog/**"
# exclude all docs
$ llmstxt gen https://vercel.com/sitemap.xml --exclude-path "**/docs/**"
Include paths for generation.
# include all docs only
$ llmstxt gen https://vercel.com/sitemap.xml --include-path "**/docs/**"
# include all blogs only
$ llmstxt gen https://vercel.com/sitemap.xml -ip "**/blog/**"
Use --replace-title to remove redundant text from your page titles. For example, dotenvx's titles all end with | dotenvx. I want to replace those with empty string.
$ llmstxt gen https://vercel.com/sitemap.xml --replace-title 's/\| dotenvx//'
Set your website's heading 1 title.
$ llmstxt gen https://vercel.com/sitemap.xml --title 'dotenvx'
Set your website's description.
$ llmstxt gen https://vercel.com/sitemap.xml --description 'This is a description'
I'm using it to generate dotenvx.com/llms.txt with the following command:
npx -y llmstxt@latest gen https://example.com/sitemap.xml -ep "**/privacy**" -ep "**/terms**" -ep "**/blog/**" -ep "**/stats/**" -ep "**/support/**" -rt 's/\| dotenvx//' -t 'dotenvx' > llms.txt
FAQs
convert `sitemap.xml` to `llms.txt`
We found that llmstxt demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.