Threat reportVulnerabilityTL-2026-1187
HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic Botnets
HalluSquatting (TL-2026-1187), also tracked as Slopsquatting, is a medium-severity software vulnerability, first published 2026-07-10. It has no confirmed attribution, affects Cursor Cursor IDE / Cursor CLI, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1187
- Threat ID
- TL-2026-1187
- Also known as
- Slopsquatting, Agentic Botnets, AI Package Hallucination Attack
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, cloud computing, enterprise it
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in HalluSquatting
Malware and tooling: Cline, Cursor, Cursor CLI, Gemini CLI, GitHub Copilot, NanoClaw, OpenClaw, Windsurf, ZeroClaw
How HalluSquatting works
HalluSquatting (a variant of slopsquatting) is a supply-chain technique where attackers register packages, repositories, and agent skills under names that LLMs are statistically likely to hallucinate, then wait for AI coding agents to autonomously fetch and execute the attacker-controlled resource. Academic research from Tel Aviv University, Technion, and Intuit (arXiv:2607.07433) demonstrated fetch rates up to 85% in repository-cloning workflows and up to 100% in agent-skill-installation workflows across nine production AI coding tools, showing the technique can achieve remote code execution at botnet-like scale without any traditional vulnerability or credential theft.
HalluSquatting exploits a well-documented failure mode of code-generating large language models: when asked to recommend, clone, or install a package, repository, or agent skill, LLMs frequently invent plausible-but-nonexistent resource names ("package hallucination"). Because the underlying training data, tokenization, and prompting patterns are shared across users, the same hallucinated name is reproduced by many different agents, users, and sessions — turning a random model error into a reliable, repeatable delivery channel. This phenomenon was first informally demonstrated in 2023 by researcher Bar Lanyado, who registered an empty package under the hallucinated name "huggingface-cli" and received over 30,000 downloads in three months after the name appeared in an LLM-authored README (Alibaba's GraphTranslator repo). The pattern was formalized and named "slopsquatting" in April 2025 by PSF Developer-in-Residence Seth Larson, and rigorously quantified in the May 2025 USENIX Security paper "We Have a Package for You!", which tested 16 models across 576,000 code samples and catalogued over 205,000 unique hallucinated package names, finding a 19.7% overall hallucination rate (21.7% for open-source models vs. 5.2% for commercial models) with 58% of hallucinated names recurring across repeated generations.
The July 2026 "Agentic Botnets" research (arXiv:2607.07433, Spira/Cohen/Feldman/Bitton/Wool/Nassi) extends this from passive package installation to fully agentic, tool-executing coding assistants — Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw. The researchers show that when these agents are asked to clone a trending repository or install an agent skill, they hallucinate an attacker-guessable identifier in up to 85% (repo cloning) and up to 100% (skill installation) of trials. An attacker who pre-registers the hallucinated name — on npm, PyPI, GitHub, or an agent-skill marketplace — and embeds an adversarial payload (a malicious install script, or a promptware-style adversarial prompt designed to manipulate the agent's subsequent reasoning) achieves remote tool execution and potential remote code execution the moment any agent fetches it. Because high-volume/trending requests concentrate hallucinations onto a small set of predictable names, a single registered resource can compromise many independent agents, users, and organizations simultaneously — an infection pattern the researchers liken to botnet propagation, without any exploitation of a software vulnerability or theft of credentials.
SOCRadar's July 10, 2026 writeup coined the public-facing name "HalluSquatting" for this technique and distinguishes it from human-driven typosquatting: the same wrong name recurs because it originates from the model's statistical behavior, not from a user's typing mistake. SOCRadar also draws the line to "promptware" — adversarial content designed to steer an agent's reasoning — noting HalluSquatting delivers the payload while promptware provides the steering. No CVE has been assigned (this is a technique/methodology, not a single software flaw), and no confirmed in-the-wild attack chain has been publicly reported as of this writing; the risk is established via controlled research across production tools rather than observed incidents, which keeps this classified MEDIUM/ACTIVE pending evidence of real-world exploitation.
MITRE ATT&CK techniques used in TL-2026-1187
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1204.002 Malicious File; T1610 Deploy Container
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools; T1199 Trusted Relationship
Impact
Persistence
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1587.001 Malware; T1608.001 Upload Malware
Reconnaissance
Affected products and versions in HalluSquatting
- Cursor — Cursor IDE / Cursor CLI
Vulnerable versions: all versions tested in research - Windsurf (Codeium) — Windsurf agentic IDE
Vulnerable versions: all versions tested in research - GitHub / Microsoft — GitHub Copilot (agentic/coding mode)
Vulnerable versions: all versions tested in research - Cline (open source) — Cline coding agent
Vulnerable versions: all versions tested in research - Google — Gemini CLI
Vulnerable versions: all versions tested in research - Unspecified — OpenClaw agentic assistant
Vulnerable versions: all versions tested in research - Unspecified — ZeroClaw agentic assistant
Vulnerable versions: all versions tested in research - Unspecified — NanoClaw agentic assistant
Vulnerable versions: all versions tested in research - npm, Inc. / OpenJS Foundation — npm package registry
Vulnerable versions: registry allows unverified publisher registration - Python Software Foundation — PyPI package registry
Vulnerable versions: registry allows unverified publisher registration
Remediation for HalluSquatting
Immediate actions
- Require search-before-fetch: validate any package/repo/skill name against the canonical registry entry before an agent installs or clones it
- Enforce human approval gates for any agent-initiated install, clone, or skill-installation action
- Restrict AI coding agent terminal/shell access; separate read, install, and execute permissions
- Allowlist approved package registries, repositories, and agent-skill marketplaces for agent use
Workarounds
- Sandbox execution of any setup/install scripts fetched by an AI coding agent
- Monitor for the co-occurrence of unknown-resource retrieval followed by terminal/shell execution as a detection signal
- Block or blocklist package/repository/skill identifiers that do not match a verified canonical name
Longer-term hardening
- Govern agent skills and plugins as enterprise assets subject to publisher verification and integrity signing
- Deploy dependency-scanning tools that flag newly published, low-reputation, or previously nonexistent package names
- Log and audit all agent tool calls, installs, and shell executions for retrospective review
- Reduce LLM sampling temperature / use conservative decoding configurations for code-generation and install-command tasks to lower hallucination frequency
- Adopt internal hallucination self-check prompting (own-output verification) as a secondary filter before install-time execution
Weaknesses (CWE) in HalluSquatting
Timeline of HalluSquatting
- Researcher Bar Lanyado identifies LLMs hallucinating the nonexistent package name "huggingface-cli" (surfaced in Alibaba's GraphTranslator README) and registers an empty package under it; it receives over 30,000 downloads in three months, providing the first empirical proof of the concept.
- PSF Developer-in-Residence Seth Larson formally coins the term "slopsquatting"; the term is popularized by Andrew Nesbitt on Mastodon.
- USENIX Security 2025 paper "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs" (UT San Antonio, Virginia Tech, Univ. of Oklahoma) tests 16 models across 576,000 samples, finding a 19.7% package hallucination rate and cataloguing over 205,000 unique hallucinated package names.
- "Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries" (arXiv:2509.22202) grounds the package-hallucination risk model in real developer query patterns, informing later agentic-fetch research such as Agentic Botnets.
- "The Range Shrinks, the Threat Remains" (arXiv:2605.17062) re-evaluates package hallucination on the 2026 frontier-model cohort, finding rates narrowed to 4.62%-6.10% but still present in every tested model.
- "Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code" (arXiv:2606.13918) publishes a statistical detection method for flagging hallucinated import/package names in AI-generated code before install-time execution, offering a candidate mitigation researchers can build tooling around.
- Researchers from Tel Aviv University, Technion, and Intuit publish "Agentic Botnets" (arXiv:2607.07433), extending hallucination-squatting from passive package installs to nine fully agentic coding tools (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, NanoClaw), demonstrating up to 85% hallucinated-fetch rates in repo cloning and up to 100% in skill installation, achieving remote tool execution/RCE.
- Threadlinqs Intelligence Platform ingests the SOCRadar advisory via RSS hunt pipeline and opens threat record TL-2026-1187 pending evidence of in-the-wild exploitation.
- SOCRadar publishes "How HalluSquatting Could Fuel Agentic Botnets," coining the public-facing name "HalluSquatting," summarizing the Agentic Botnets research, and issuing detection/governance recommendations for enterprises using AI coding agents.
Sources cited for HalluSquatting
- How HalluSquatting Could Fuel Agentic Botnets
- Agentic Botnets research project page
- Agentic Botnets (arXiv:2607.07433)
- The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort
- Slopsquatting - Wikipedia
- The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain Attacks
- AI Slopsquatting: How LLM Hallucinations Poison Your Code
- Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code
- Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries
- Slopsquatting: The AI Package Hallucination Attack Already Happening
Detection coverage for TL-2026-1187
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1187 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.