# HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names

> Academic researchers (Tel Aviv University, Technion, Intuit) demonstrated 'HalluSquatting' (aka Adversarial Hallucination Squatting), a class of scalable, untargeted promptware attacks that exploit AI coding assistants' tendency to hallucinate plausible-but-nonexistent repository, package, and skill names. Attackers pre-register these predicted hallucinated names on GitHub, npm, and plugin marketplaces with embedded adversarial instructions; when a victim's AI assistant later hallucinates the same name and auto-fetches/installs it, the assistant's built-in terminal/tool-execution capability runs the attacker's planted commands, enabling remote code execution and scalable botnet-style device compromise.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1164
- **ID:** TL-2026-1164
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

HalluSquatting was disclosed by researchers Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi (Tel Aviv University, Technion, and Intuit), the same group behind prior work on self-spreading AI email worms (Morris II) and Google Gemini calendar-invite prompt injection. The attack targets nine widely used AI coding assistants and CLIs: Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw.

The attack chain runs in six phases: (1) Preparation — attackers identify trending repositories, tools, or skills and repeatedly probe target LLMs across varied phrasings and multiple foundation models to calculate the highest-probability hallucinated identifier for a given resource; (2) Trigger — a legitimate user asks their AI assistant to clone a repository, install a package, or install a 'skill'/plugin; (3) Planning — the agentic framework's planner formulates the actions needed to satisfy the request; (4) Hallucination — the underlying LLM outputs an incorrect resource name/location that happens to match the name the attacker has already registered; (5) Retrieval — the assistant's tool-use layer fetches the attacker-controlled resource (git clone, npm install, marketplace install) without verifying it resolves to a legitimate, previously-known source; (6) Context Poisoning & Tool Invocation — adversarial instructions embedded in the fetched resource are read into the assistant's context and, combined with auto-run/auto-execute terminal access, are executed as commands, installing a persistent bot agent on the victim's device.

Measured hallucination consistency was high enough to make the attack reliable at scale: up to 85% for repository-clone requests and up to 100% for skill/plugin install requests, with hallucinations transferring across different foundation models and prompt phrasings — meaning a single pre-registered squatted name can trap users of many different assistants. Researchers used only harmless placeholder payloads (not functional malware) for ethical/responsible-disclosure reasons, and withheld precise reproduction steps and target-specific hallucinated names from the public write-up; findings were privately disclosed to affected vendors, foundation model providers, and marketplace maintainers ahead of publication. The paper appears on arXiv as 2607.07433v1 and was presented at RWAISec'26 and discussed in a BlackHat webinar.

HalluSquatting builds on and generalizes 'slopsquatting', an earlier and now actively-exploited-in-the-wild variant limited to package-manager names. The canonical real-world slopsquatting case is 'react-codeshift': a nonexistent npm package name invented by an LLM that conflated two real tools (jscodeshift and react-codemod). The hallucinated name first appeared, unreviewed, in a single commit of 47 LLM-generated Agent Skills on GitHub, then propagated to 237 repositories via forks and translation (including into Japanese) before Aikido Security researcher Charlie Eriksen discovered and pre-registered it defensively; AI coding agents continued to attempt `npx` installs of the name daily even after Eriksen's claim. Separately, Palo Alto Networks Unit 42 catalogued roughly 250,000 unregistered domains that AI models hallucinate ('phantom squatting'), representing a large pre-existing pool of squattable names beyond code repositories/packages.

HalluSquatting represents an architectural trust weakness rather than a single software flaw: agentic coding tools resolve resource names supplied by an LLM as if they were ground truth, and then couple that unverified resolution to auto-execution/auto-run terminal capability. No CVE applies because the weakness is systemic across the agentic-AI-tooling category rather than isolated to one implementation.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1583.008 Malvertising
- T1586 Compromise Accounts
- T1608.001 Upload Malware
- T1195.002 Compromise Software Supply Chain
- T1566 Phishing
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1204.002 Malicious File
- T1059.009 Cloud API
- T1505.003 Web Shell
- T1547 Boot or Logon Autostart Execution
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1496 Resource Hijacking
- T1005 Data from Local System

## Sources

- [New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware](https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html)
- [Agentic Botnets — HalluSquatting research site](https://sites.google.com/view/agentic-botnets/home)
- [HalluSquatting / Agentic Botnets paper (arXiv 2607.07433v1)](https://arxiv.org/abs/2607.07433v1)
- [New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware](https://cybersecuritynews.com/hallusquatting-attack-poison-ai-coding-assistants/amp/)
- [Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants](https://cyberpress.org/agentic-botnets-hallusquatting-ai-coding/)
- [HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers](https://gbhackers.com/hallusquatting-attack/)
- [HalluSquatting attack turns 9 AI coding assistants into a botnet vector](https://www.aichatdaily.com/ai-security/hallusquatting-attack-turns-9-ai-coding-assistants-into)
- [Slopsquatting: The AI Package Hallucination Attack Already Happening](https://www.aikido.dev/blog/slopsquatting-ai-package-hallucination-attacks)
- [AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It](https://www.techtimes.com/articles/319457/20260701/ai-coding-agents-skip-package-verification-attackers-are-exploiting-it.htm)
- [Supply-chain attacks take aim at your AI coding agents](https://www.csoonline.com/article/4167465/supply-chain-attacks-take-aim-at-your-ai-coding-agents.html)
- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/)
- [Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications (Morris II, arXiv 2403.02817)](https://arxiv.org/abs/2403.02817)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1164
