Threat reportVulnerabilityTL-2026-1164

HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names

mediumACTIVE

HalluSquatting (TL-2026-1164), also tracked as HalluSquatting, is a medium-severity software vulnerability, first published 2026-07-10. It has no confirmed attribution, affects Anysphere Cursor, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1164

Threat ID
TL-2026-1164
Also known as
HalluSquatting, Adversarial Hallucination Squatting, Agentic Botnets
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, all-sectors-using-ai-coding-tools
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in HalluSquatting

Malware and tooling: Cline, Cursor, Cursor CLI, GitHub Copilot, Google Gemini CLI, NanoClaw, OpenClaw, Windsurf, ZeroClaw

How HalluSquatting works

Academic researchers (Tel Aviv University, Technion, Intuit) demonstrated 'HalluSquatting' (aka Adversarial Hallucination Squatting), a class of scalable, untargeted promptware attacks that exploit AI coding assistants' tendency to hallucinate plausible-but-nonexistent repository, package, and skill names. Attackers pre-register these predicted hallucinated names on GitHub, npm, and plugin marketplaces with embedded adversarial instructions; when a victim's AI assistant later hallucinates the same name and auto-fetches/installs it, the assistant's built-in terminal/tool-execution capability runs the attacker's planted commands, enabling remote code execution and scalable botnet-style device compromise.

HalluSquatting was disclosed by researchers Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi (Tel Aviv University, Technion, and Intuit), the same group behind prior work on self-spreading AI email worms (Morris II) and Google Gemini calendar-invite prompt injection. The attack targets nine widely used AI coding assistants and CLIs: Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw.

The attack chain runs in six phases: (1) Preparation — attackers identify trending repositories, tools, or skills and repeatedly probe target LLMs across varied phrasings and multiple foundation models to calculate the highest-probability hallucinated identifier for a given resource; (2) Trigger — a legitimate user asks their AI assistant to clone a repository, install a package, or install a 'skill'/plugin; (3) Planning — the agentic framework's planner formulates the actions needed to satisfy the request; (4) Hallucination — the underlying LLM outputs an incorrect resource name/location that happens to match the name the attacker has already registered; (5) Retrieval — the assistant's tool-use layer fetches the attacker-controlled resource (git clone, npm install, marketplace install) without verifying it resolves to a legitimate, previously-known source; (6) Context Poisoning & Tool Invocation — adversarial instructions embedded in the fetched resource are read into the assistant's context and, combined with auto-run/auto-execute terminal access, are executed as commands, installing a persistent bot agent on the victim's device.

Measured hallucination consistency was high enough to make the attack reliable at scale: up to 85% for repository-clone requests and up to 100% for skill/plugin install requests, with hallucinations transferring across different foundation models and prompt phrasings — meaning a single pre-registered squatted name can trap users of many different assistants. Researchers used only harmless placeholder payloads (not functional malware) for ethical/responsible-disclosure reasons, and withheld precise reproduction steps and target-specific hallucinated names from the public write-up; findings were privately disclosed to affected vendors, foundation model providers, and marketplace maintainers ahead of publication. The paper appears on arXiv as 2607.07433v1 and was presented at RWAISec'26 and discussed in a BlackHat webinar.

HalluSquatting builds on and generalizes 'slopsquatting', an earlier and now actively-exploited-in-the-wild variant limited to package-manager names. The canonical real-world slopsquatting case is 'react-codeshift': a nonexistent npm package name invented by an LLM that conflated two real tools (jscodeshift and react-codemod). The hallucinated name first appeared, unreviewed, in a single commit of 47 LLM-generated Agent Skills on GitHub, then propagated to 237 repositories via forks and translation (including into Japanese) before Aikido Security researcher Charlie Eriksen discovered and pre-registered it defensively; AI coding agents continued to attempt `npx` installs of the name daily even after Eriksen's claim. Separately, Palo Alto Networks Unit 42 catalogued roughly 250,000 unregistered domains that AI models hallucinate ('phantom squatting'), representing a large pre-existing pool of squattable names beyond code repositories/packages.

HalluSquatting represents an architectural trust weakness rather than a single software flaw: agentic coding tools resolve resource names supplied by an LLM as if they were ground truth, and then couple that unverified resolution to auto-execution/auto-run terminal capability. No CVE applies because the weakness is systemic across the agentic-AI-tooling category rather than isolated to one implementation.

MITRE ATT&CK techniques used in TL-2026-1164

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Execution

T1059 Command and Scripting Interpreter; T1059.009 Cloud API; T1204.002 Malicious File

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship; T1566 Phishing

Impact

T1496 Resource Hijacking

Persistence

T1505.003 Web Shell; T1547 Boot or Logon Autostart Execution

Resource Development

T1583.008 Malvertising; T1585 Establish Accounts; T1586 Compromise Accounts; T1608.001 Upload Malware

Affected products and versions in HalluSquatting

  • Anysphere — Cursor
    Vulnerable versions: all versions tested with auto-run enabled, 2026
  • Anysphere — Cursor CLI
    Vulnerable versions: all versions tested with auto-run enabled, 2026
  • Codeium (Windsurf) — Windsurf
    Vulnerable versions: all versions tested with auto-run enabled, 2026
  • Microsoft/GitHub — GitHub Copilot
    Vulnerable versions: all versions tested with auto-run/agent mode enabled, 2026
  • Cline (open source) — Cline
    Vulnerable versions: all versions tested with auto-approve enabled, 2026
  • Google — Gemini CLI
    Vulnerable versions: all versions tested with YOLO/auto-accept mode enabled, 2026
  • OpenClaw family — OpenClaw
    Vulnerable versions: all versions tested, 2026
  • OpenClaw family — ZeroClaw
    Vulnerable versions: all versions tested, 2026
  • OpenClaw family — NanoClaw
    Vulnerable versions: all versions tested, 2026
  • npm / GitHub / plugin marketplaces (ecosystem-wide) — Package/repository/plugin name-resolution trust model
    Vulnerable versions: current registration model with no hallucinated-name reservation, 2026

Remediation for HalluSquatting

Immediate actions

  • Disable auto-run / auto-approve modes on AI coding assistants (e.g., Claude Code's skip-permissions flag, Gemini CLI's YOLO mode) so terminal commands require human review before execution
  • Treat AI-suggested repository, package, and skill/plugin names as unverified guesses, not facts — manually confirm the name resolves to a known, previously-established legitimate source before allowing clone/install
  • Flag and gate high-risk agent actions (git clone, package install, plugin/skill install, curl|bash-style fetch-and-execute) behind explicit human confirmation regardless of assistant settings
  • Audit recent AI-assisted commits and Agent Skill definitions for unreviewed, LLM-invented dependency or repository references

Workarounds

  • Pin coding agents to explicit, human-vetted repository URLs, package names with lockfiles, and pre-approved skill/plugin manifests instead of natural-language resource requests
  • Run AI coding assistants with restricted/sandboxed terminal execution and network egress controls to limit blast radius if a squatted resource is fetched

Longer-term hardening

  • Adopt agent architectures that require the planner to search/verify a resource's existence and provenance before fetching it, rather than fetching on the LLM's first-guess name
  • Deploy pre-execution safety layers that inspect and validate agent tool-invocations against an allowlist of known-good sources (e.g., Claude Code permission/auto modes, Gemini CLI Conseca-style guardrails)
  • Package registries and code-hosting/plugin marketplaces should prevent re-registration or squatting of names that closely match well-known, high-trend repositories/packages, mirroring domain typosquatting defenses
  • Registries/marketplaces should proactively pre-register or reserve high-probability AI-hallucinated names for popular projects before attackers can claim them
  • Contribute telemetry on repeated hallucinated-name requests back to foundation model providers to reduce hallucination rates for high-trend resource names

Weaknesses (CWE) in HalluSquatting

CWE-1021, CWE-345, CWE-494, CWE-829

Timeline of HalluSquatting

  • The same core research group (Stav Cohen, Ron Bitton, Ben Nassi, Cornell Tech) publishes 'Here Comes The AI Worm' (arXiv 2403.02817), disclosing the Morris II zero-click generative-AI worm — prior foundational work establishing the researchers' track record on self-propagating/agentic-AI-exploiting attacks that HalluSquatting extends.
  • Aikido Security researcher Charlie Eriksen discovers 'react-codeshift', a nonexistent npm package invented by an LLM, already spread to 237 repositories via unreviewed AI-generated Agent Skills; he defensively pre-registers the name.
  • Cloud Security Alliance AI Safety Initiative (CSAI Foundation) publishes a research note on slopsquatting as an AI supply-chain risk.
  • CSO Online / InfoWorld publish coverage on supply-chain attacks targeting AI coding agents broadly, framing the ecosystem-wide risk ahead of the HalluSquatting disclosure.
  • Palo Alto Networks Unit 42 publishes 'Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector', analyzing 913 global brands across 685,339 prompts and cataloguing ~250,000 unregistered hallucinated domains plus 13,229 confirmed-malicious URLs, including a Montana Empire phishing kit and a malicious APK campaign impersonating a national postal service — establishing the broader hallucinated-namespace attack surface HalluSquatting builds on.
  • Tech Times covers findings that AI coding agents routinely skip package verification and that attackers are already exploiting the gap.
  • Spira, Cohen, Feldman, Bitton, Wool, and Nassi publish the HalluSquatting / 'Agentic Botnets' research (arXiv 2607.07433v1) and stand up the accompanying research site, after completing responsible disclosure to affected vendors and marketplace maintainers.
  • TL-Intel-Harness ingests the HalluSquatting story from The Hacker News RSS feed and opens threat TL-2026-1164 for tracking.
  • The Hacker News and multiple security outlets (CyberSecurityNews, CyberPress, GBHackers, AI Chat Daily) publish coverage of the HalluSquatting attack, detailing the six-phase attack chain and 85%/100% hallucination consistency rates across nine AI coding assistants.

Sources cited for HalluSquatting

Detection coverage for TL-2026-1164

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1164 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats