Threat reportVulnerabilityTL-2026-1187

HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic Botnets

mediumACTIVE

HalluSquatting (TL-2026-1187), also tracked as Slopsquatting, is a medium-severity software vulnerability, first published 2026-07-10. It has no confirmed attribution, affects Cursor Cursor IDE / Cursor CLI, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1187

Threat ID
TL-2026-1187
Also known as
Slopsquatting, Agentic Botnets, AI Package Hallucination Attack
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software development, cloud computing, enterprise it
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in HalluSquatting

Malware and tooling: Cline, Cursor, Cursor CLI, Gemini CLI, GitHub Copilot, NanoClaw, OpenClaw, Windsurf, ZeroClaw

How HalluSquatting works

HalluSquatting (a variant of slopsquatting) is a supply-chain technique where attackers register packages, repositories, and agent skills under names that LLMs are statistically likely to hallucinate, then wait for AI coding agents to autonomously fetch and execute the attacker-controlled resource. Academic research from Tel Aviv University, Technion, and Intuit (arXiv:2607.07433) demonstrated fetch rates up to 85% in repository-cloning workflows and up to 100% in agent-skill-installation workflows across nine production AI coding tools, showing the technique can achieve remote code execution at botnet-like scale without any traditional vulnerability or credential theft.

HalluSquatting exploits a well-documented failure mode of code-generating large language models: when asked to recommend, clone, or install a package, repository, or agent skill, LLMs frequently invent plausible-but-nonexistent resource names ("package hallucination"). Because the underlying training data, tokenization, and prompting patterns are shared across users, the same hallucinated name is reproduced by many different agents, users, and sessions — turning a random model error into a reliable, repeatable delivery channel. This phenomenon was first informally demonstrated in 2023 by researcher Bar Lanyado, who registered an empty package under the hallucinated name "huggingface-cli" and received over 30,000 downloads in three months after the name appeared in an LLM-authored README (Alibaba's GraphTranslator repo). The pattern was formalized and named "slopsquatting" in April 2025 by PSF Developer-in-Residence Seth Larson, and rigorously quantified in the May 2025 USENIX Security paper "We Have a Package for You!", which tested 16 models across 576,000 code samples and catalogued over 205,000 unique hallucinated package names, finding a 19.7% overall hallucination rate (21.7% for open-source models vs. 5.2% for commercial models) with 58% of hallucinated names recurring across repeated generations.

The July 2026 "Agentic Botnets" research (arXiv:2607.07433, Spira/Cohen/Feldman/Bitton/Wool/Nassi) extends this from passive package installation to fully agentic, tool-executing coding assistants — Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw. The researchers show that when these agents are asked to clone a trending repository or install an agent skill, they hallucinate an attacker-guessable identifier in up to 85% (repo cloning) and up to 100% (skill installation) of trials. An attacker who pre-registers the hallucinated name — on npm, PyPI, GitHub, or an agent-skill marketplace — and embeds an adversarial payload (a malicious install script, or a promptware-style adversarial prompt designed to manipulate the agent's subsequent reasoning) achieves remote tool execution and potential remote code execution the moment any agent fetches it. Because high-volume/trending requests concentrate hallucinations onto a small set of predictable names, a single registered resource can compromise many independent agents, users, and organizations simultaneously — an infection pattern the researchers liken to botnet propagation, without any exploitation of a software vulnerability or theft of credentials.

SOCRadar's July 10, 2026 writeup coined the public-facing name "HalluSquatting" for this technique and distinguishes it from human-driven typosquatting: the same wrong name recurs because it originates from the model's statistical behavior, not from a user's typing mistake. SOCRadar also draws the line to "promptware" — adversarial content designed to steer an agent's reasoning — noting HalluSquatting delivers the payload while promptware provides the steering. No CVE has been assigned (this is a technique/methodology, not a single software flaw), and no confirmed in-the-wild attack chain has been publicly reported as of this writing; the risk is established via controlled research across production tools rather than observed incidents, which keeps this classified MEDIUM/ACTIVE pending evidence of real-world exploitation.

MITRE ATT&CK techniques used in TL-2026-1187

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1204.002 Malicious File; T1610 Deploy Container

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools; T1199 Trusted Relationship

Impact

T1496 Resource Hijacking

Persistence

T1505.003 Web Shell

Resource Development

T1583.001 Domains; T1585.001 Social Media Accounts; T1587.001 Malware; T1608.001 Upload Malware

Reconnaissance

T1591 Gather Victim Org Information

Affected products and versions in HalluSquatting

  • Cursor — Cursor IDE / Cursor CLI
    Vulnerable versions: all versions tested in research
  • Windsurf (Codeium) — Windsurf agentic IDE
    Vulnerable versions: all versions tested in research
  • GitHub / Microsoft — GitHub Copilot (agentic/coding mode)
    Vulnerable versions: all versions tested in research
  • Cline (open source) — Cline coding agent
    Vulnerable versions: all versions tested in research
  • Google — Gemini CLI
    Vulnerable versions: all versions tested in research
  • Unspecified — OpenClaw agentic assistant
    Vulnerable versions: all versions tested in research
  • Unspecified — ZeroClaw agentic assistant
    Vulnerable versions: all versions tested in research
  • Unspecified — NanoClaw agentic assistant
    Vulnerable versions: all versions tested in research
  • npm, Inc. / OpenJS Foundation — npm package registry
    Vulnerable versions: registry allows unverified publisher registration
  • Python Software Foundation — PyPI package registry
    Vulnerable versions: registry allows unverified publisher registration

Remediation for HalluSquatting

Immediate actions

  • Require search-before-fetch: validate any package/repo/skill name against the canonical registry entry before an agent installs or clones it
  • Enforce human approval gates for any agent-initiated install, clone, or skill-installation action
  • Restrict AI coding agent terminal/shell access; separate read, install, and execute permissions
  • Allowlist approved package registries, repositories, and agent-skill marketplaces for agent use

Workarounds

  • Sandbox execution of any setup/install scripts fetched by an AI coding agent
  • Monitor for the co-occurrence of unknown-resource retrieval followed by terminal/shell execution as a detection signal
  • Block or blocklist package/repository/skill identifiers that do not match a verified canonical name

Longer-term hardening

  • Govern agent skills and plugins as enterprise assets subject to publisher verification and integrity signing
  • Deploy dependency-scanning tools that flag newly published, low-reputation, or previously nonexistent package names
  • Log and audit all agent tool calls, installs, and shell executions for retrospective review
  • Reduce LLM sampling temperature / use conservative decoding configurations for code-generation and install-command tasks to lower hallucination frequency
  • Adopt internal hallucination self-check prompting (own-output verification) as a secondary filter before install-time execution

Weaknesses (CWE) in HalluSquatting

CWE-829, CWE-1357

Timeline of HalluSquatting

  • Researcher Bar Lanyado identifies LLMs hallucinating the nonexistent package name "huggingface-cli" (surfaced in Alibaba's GraphTranslator README) and registers an empty package under it; it receives over 30,000 downloads in three months, providing the first empirical proof of the concept.
  • PSF Developer-in-Residence Seth Larson formally coins the term "slopsquatting"; the term is popularized by Andrew Nesbitt on Mastodon.
  • USENIX Security 2025 paper "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs" (UT San Antonio, Virginia Tech, Univ. of Oklahoma) tests 16 models across 576,000 samples, finding a 19.7% package hallucination rate and cataloguing over 205,000 unique hallucinated package names.
  • "Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries" (arXiv:2509.22202) grounds the package-hallucination risk model in real developer query patterns, informing later agentic-fetch research such as Agentic Botnets.
  • "The Range Shrinks, the Threat Remains" (arXiv:2605.17062) re-evaluates package hallucination on the 2026 frontier-model cohort, finding rates narrowed to 4.62%-6.10% but still present in every tested model.
  • "Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code" (arXiv:2606.13918) publishes a statistical detection method for flagging hallucinated import/package names in AI-generated code before install-time execution, offering a candidate mitigation researchers can build tooling around.
  • Researchers from Tel Aviv University, Technion, and Intuit publish "Agentic Botnets" (arXiv:2607.07433), extending hallucination-squatting from passive package installs to nine fully agentic coding tools (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, NanoClaw), demonstrating up to 85% hallucinated-fetch rates in repo cloning and up to 100% in skill installation, achieving remote tool execution/RCE.
  • Threadlinqs Intelligence Platform ingests the SOCRadar advisory via RSS hunt pipeline and opens threat record TL-2026-1187 pending evidence of in-the-wild exploitation.
  • SOCRadar publishes "How HalluSquatting Could Fuel Agentic Botnets," coining the public-facing name "HalluSquatting," summarizing the Agentic Botnets research, and issuing detection/governance recommendations for enterprises using AI coding agents.

Sources cited for HalluSquatting

Detection coverage for TL-2026-1187

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1187 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats