Threat reportVulnerabilityTL-2026-1164
HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names
HalluSquatting (TL-2026-1164), also tracked as HalluSquatting, is a medium-severity software vulnerability, first published 2026-07-10. It has no confirmed attribution, affects Anysphere Cursor, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1164
- Threat ID
- TL-2026-1164
- Also known as
- HalluSquatting, Adversarial Hallucination Squatting, Agentic Botnets
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, all-sectors-using-ai-coding-tools
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in HalluSquatting
Malware and tooling: Cline, Cursor, Cursor CLI, GitHub Copilot, Google Gemini CLI, NanoClaw, OpenClaw, Windsurf, ZeroClaw
How HalluSquatting works
Academic researchers (Tel Aviv University, Technion, Intuit) demonstrated 'HalluSquatting' (aka Adversarial Hallucination Squatting), a class of scalable, untargeted promptware attacks that exploit AI coding assistants' tendency to hallucinate plausible-but-nonexistent repository, package, and skill names. Attackers pre-register these predicted hallucinated names on GitHub, npm, and plugin marketplaces with embedded adversarial instructions; when a victim's AI assistant later hallucinates the same name and auto-fetches/installs it, the assistant's built-in terminal/tool-execution capability runs the attacker's planted commands, enabling remote code execution and scalable botnet-style device compromise.
HalluSquatting was disclosed by researchers Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi (Tel Aviv University, Technion, and Intuit), the same group behind prior work on self-spreading AI email worms (Morris II) and Google Gemini calendar-invite prompt injection. The attack targets nine widely used AI coding assistants and CLIs: Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw.
The attack chain runs in six phases: (1) Preparation — attackers identify trending repositories, tools, or skills and repeatedly probe target LLMs across varied phrasings and multiple foundation models to calculate the highest-probability hallucinated identifier for a given resource; (2) Trigger — a legitimate user asks their AI assistant to clone a repository, install a package, or install a 'skill'/plugin; (3) Planning — the agentic framework's planner formulates the actions needed to satisfy the request; (4) Hallucination — the underlying LLM outputs an incorrect resource name/location that happens to match the name the attacker has already registered; (5) Retrieval — the assistant's tool-use layer fetches the attacker-controlled resource (git clone, npm install, marketplace install) without verifying it resolves to a legitimate, previously-known source; (6) Context Poisoning & Tool Invocation — adversarial instructions embedded in the fetched resource are read into the assistant's context and, combined with auto-run/auto-execute terminal access, are executed as commands, installing a persistent bot agent on the victim's device.
Measured hallucination consistency was high enough to make the attack reliable at scale: up to 85% for repository-clone requests and up to 100% for skill/plugin install requests, with hallucinations transferring across different foundation models and prompt phrasings — meaning a single pre-registered squatted name can trap users of many different assistants. Researchers used only harmless placeholder payloads (not functional malware) for ethical/responsible-disclosure reasons, and withheld precise reproduction steps and target-specific hallucinated names from the public write-up; findings were privately disclosed to affected vendors, foundation model providers, and marketplace maintainers ahead of publication. The paper appears on arXiv as 2607.07433v1 and was presented at RWAISec'26 and discussed in a BlackHat webinar.
HalluSquatting builds on and generalizes 'slopsquatting', an earlier and now actively-exploited-in-the-wild variant limited to package-manager names. The canonical real-world slopsquatting case is 'react-codeshift': a nonexistent npm package name invented by an LLM that conflated two real tools (jscodeshift and react-codemod). The hallucinated name first appeared, unreviewed, in a single commit of 47 LLM-generated Agent Skills on GitHub, then propagated to 237 repositories via forks and translation (including into Japanese) before Aikido Security researcher Charlie Eriksen discovered and pre-registered it defensively; AI coding agents continued to attempt `npx` installs of the name daily even after Eriksen's claim. Separately, Palo Alto Networks Unit 42 catalogued roughly 250,000 unregistered domains that AI models hallucinate ('phantom squatting'), representing a large pre-existing pool of squattable names beyond code repositories/packages.
HalluSquatting represents an architectural trust weakness rather than a single software flaw: agentic coding tools resolve resource names supplied by an LLM as if they were ground truth, and then couple that unverified resolution to auto-execution/auto-run terminal capability. No CVE applies because the weakness is systemic across the agentic-AI-tooling category rather than isolated to one implementation.
MITRE ATT&CK techniques used in TL-2026-1164
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Execution
T1059 Command and Scripting Interpreter; T1059.009 Cloud API; T1204.002 Malicious File
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship; T1566 Phishing
Impact
Persistence
T1505.003 Web Shell; T1547 Boot or Logon Autostart Execution
Resource Development
T1583.008 Malvertising; T1585 Establish Accounts; T1586 Compromise Accounts; T1608.001 Upload Malware
Affected products and versions in HalluSquatting
- Anysphere — Cursor
Vulnerable versions: all versions tested with auto-run enabled, 2026 - Anysphere — Cursor CLI
Vulnerable versions: all versions tested with auto-run enabled, 2026 - Codeium (Windsurf) — Windsurf
Vulnerable versions: all versions tested with auto-run enabled, 2026 - Microsoft/GitHub — GitHub Copilot
Vulnerable versions: all versions tested with auto-run/agent mode enabled, 2026 - Cline (open source) — Cline
Vulnerable versions: all versions tested with auto-approve enabled, 2026 - Google — Gemini CLI
Vulnerable versions: all versions tested with YOLO/auto-accept mode enabled, 2026 - OpenClaw family — OpenClaw
Vulnerable versions: all versions tested, 2026 - OpenClaw family — ZeroClaw
Vulnerable versions: all versions tested, 2026 - OpenClaw family — NanoClaw
Vulnerable versions: all versions tested, 2026 - npm / GitHub / plugin marketplaces (ecosystem-wide) — Package/repository/plugin name-resolution trust model
Vulnerable versions: current registration model with no hallucinated-name reservation, 2026
Remediation for HalluSquatting
Immediate actions
- Disable auto-run / auto-approve modes on AI coding assistants (e.g., Claude Code's skip-permissions flag, Gemini CLI's YOLO mode) so terminal commands require human review before execution
- Treat AI-suggested repository, package, and skill/plugin names as unverified guesses, not facts — manually confirm the name resolves to a known, previously-established legitimate source before allowing clone/install
- Flag and gate high-risk agent actions (git clone, package install, plugin/skill install, curl|bash-style fetch-and-execute) behind explicit human confirmation regardless of assistant settings
- Audit recent AI-assisted commits and Agent Skill definitions for unreviewed, LLM-invented dependency or repository references
Workarounds
- Pin coding agents to explicit, human-vetted repository URLs, package names with lockfiles, and pre-approved skill/plugin manifests instead of natural-language resource requests
- Run AI coding assistants with restricted/sandboxed terminal execution and network egress controls to limit blast radius if a squatted resource is fetched
Longer-term hardening
- Adopt agent architectures that require the planner to search/verify a resource's existence and provenance before fetching it, rather than fetching on the LLM's first-guess name
- Deploy pre-execution safety layers that inspect and validate agent tool-invocations against an allowlist of known-good sources (e.g., Claude Code permission/auto modes, Gemini CLI Conseca-style guardrails)
- Package registries and code-hosting/plugin marketplaces should prevent re-registration or squatting of names that closely match well-known, high-trend repositories/packages, mirroring domain typosquatting defenses
- Registries/marketplaces should proactively pre-register or reserve high-probability AI-hallucinated names for popular projects before attackers can claim them
- Contribute telemetry on repeated hallucinated-name requests back to foundation model providers to reduce hallucination rates for high-trend resource names
Weaknesses (CWE) in HalluSquatting
Timeline of HalluSquatting
- The same core research group (Stav Cohen, Ron Bitton, Ben Nassi, Cornell Tech) publishes 'Here Comes The AI Worm' (arXiv 2403.02817), disclosing the Morris II zero-click generative-AI worm — prior foundational work establishing the researchers' track record on self-propagating/agentic-AI-exploiting attacks that HalluSquatting extends.
- Aikido Security researcher Charlie Eriksen discovers 'react-codeshift', a nonexistent npm package invented by an LLM, already spread to 237 repositories via unreviewed AI-generated Agent Skills; he defensively pre-registers the name.
- Cloud Security Alliance AI Safety Initiative (CSAI Foundation) publishes a research note on slopsquatting as an AI supply-chain risk.
- CSO Online / InfoWorld publish coverage on supply-chain attacks targeting AI coding agents broadly, framing the ecosystem-wide risk ahead of the HalluSquatting disclosure.
- Palo Alto Networks Unit 42 publishes 'Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector', analyzing 913 global brands across 685,339 prompts and cataloguing ~250,000 unregistered hallucinated domains plus 13,229 confirmed-malicious URLs, including a Montana Empire phishing kit and a malicious APK campaign impersonating a national postal service — establishing the broader hallucinated-namespace attack surface HalluSquatting builds on.
- Tech Times covers findings that AI coding agents routinely skip package verification and that attackers are already exploiting the gap.
- Spira, Cohen, Feldman, Bitton, Wool, and Nassi publish the HalluSquatting / 'Agentic Botnets' research (arXiv 2607.07433v1) and stand up the accompanying research site, after completing responsible disclosure to affected vendors and marketplace maintainers.
- TL-Intel-Harness ingests the HalluSquatting story from The Hacker News RSS feed and opens threat TL-2026-1164 for tracking.
- The Hacker News and multiple security outlets (CyberSecurityNews, CyberPress, GBHackers, AI Chat Daily) publish coverage of the HalluSquatting attack, detailing the six-phase attack chain and 85%/100% hallucination consistency rates across nine AI coding assistants.
Sources cited for HalluSquatting
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
- Agentic Botnets — HalluSquatting research site
- HalluSquatting / Agentic Botnets paper (arXiv 2607.07433v1)
- New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware
- Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants
- HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers
- HalluSquatting attack turns 9 AI coding assistants into a botnet vector
- Slopsquatting: The AI Package Hallucination Attack Already Happening
- AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It
- Supply-chain attacks take aim at your AI coding agents
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
- Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications (Morris II, arXiv 2403.02817)
Detection coverage for TL-2026-1164
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1164 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.