# HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic Botnets

> HalluSquatting (a variant of slopsquatting) is a supply-chain technique where attackers register packages, repositories, and agent skills under names that LLMs are statistically likely to hallucinate, then wait for AI coding agents to autonomously fetch and execute the attacker-controlled resource. Academic research from Tel Aviv University, Technion, and Intuit (arXiv:2607.07433) demonstrated fetch rates up to 85% in repository-cloning workflows and up to 100% in agent-skill-installation workflows across nine production AI coding tools, showing the technique can achieve remote code execution at botnet-like scale without any traditional vulnerability or credential theft.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1187
- **ID:** TL-2026-1187
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

HalluSquatting exploits a well-documented failure mode of code-generating large language models: when asked to recommend, clone, or install a package, repository, or agent skill, LLMs frequently invent plausible-but-nonexistent resource names ("package hallucination"). Because the underlying training data, tokenization, and prompting patterns are shared across users, the same hallucinated name is reproduced by many different agents, users, and sessions — turning a random model error into a reliable, repeatable delivery channel. This phenomenon was first informally demonstrated in 2023 by researcher Bar Lanyado, who registered an empty package under the hallucinated name "huggingface-cli" and received over 30,000 downloads in three months after the name appeared in an LLM-authored README (Alibaba's GraphTranslator repo). The pattern was formalized and named "slopsquatting" in April 2025 by PSF Developer-in-Residence Seth Larson, and rigorously quantified in the May 2025 USENIX Security paper "We Have a Package for You!", which tested 16 models across 576,000 code samples and catalogued over 205,000 unique hallucinated package names, finding a 19.7% overall hallucination rate (21.7% for open-source models vs. 5.2% for commercial models) with 58% of hallucinated names recurring across repeated generations.

The July 2026 "Agentic Botnets" research (arXiv:2607.07433, Spira/Cohen/Feldman/Bitton/Wool/Nassi) extends this from passive package installation to fully agentic, tool-executing coding assistants — Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, and NanoClaw. The researchers show that when these agents are asked to clone a trending repository or install an agent skill, they hallucinate an attacker-guessable identifier in up to 85% (repo cloning) and up to 100% (skill installation) of trials. An attacker who pre-registers the hallucinated name — on npm, PyPI, GitHub, or an agent-skill marketplace — and embeds an adversarial payload (a malicious install script, or a promptware-style adversarial prompt designed to manipulate the agent's subsequent reasoning) achieves remote tool execution and potential remote code execution the moment any agent fetches it. Because high-volume/trending requests concentrate hallucinations onto a small set of predictable names, a single registered resource can compromise many independent agents, users, and organizations simultaneously — an infection pattern the researchers liken to botnet propagation, without any exploitation of a software vulnerability or theft of credentials.

SOCRadar's July 10, 2026 writeup coined the public-facing name "HalluSquatting" for this technique and distinguishes it from human-driven typosquatting: the same wrong name recurs because it originates from the model's statistical behavior, not from a user's typing mistake. SOCRadar also draws the line to "promptware" — adversarial content designed to steer an agent's reasoning — noting HalluSquatting delivers the payload while promptware provides the steering. No CVE has been assigned (this is a technique/methodology, not a single software flaw), and no confirmed in-the-wild attack chain has been publicly reported as of this writing; the risk is established via controlled research across production tools rather than observed incidents, which keeps this classified MEDIUM/ACTIVE pending evidence of real-world exploitation.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1587.001 Malware
- T1583.001 Domains
- T1585.001 Social Media Accounts
- T1608.001 Upload Malware
- T1195.001 Compromise Software Dependencies and Development Tools
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1204.002 Malicious File
- T1610 Deploy Container
- T1505.003 Web Shell
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1105 Ingress Tool Transfer
- T1071.001 Web Protocols
- T1005 Data from Local System
- T1041 Exfiltration Over C2 Channel
- T1496 Resource Hijacking

## Sources

- [How HalluSquatting Could Fuel Agentic Botnets](https://socradar.io/blog/hallusquatting-agentic-botnets/)
- [Agentic Botnets research project page](https://sites.google.com/view/agentic-botnets/home)
- [Agentic Botnets (arXiv:2607.07433)](https://arxiv.org/abs/2607.07433)
- [The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort](https://arxiv.org/abs/2605.17062)
- [Slopsquatting - Wikipedia](https://en.wikipedia.org/wiki/Slopsquatting)
- [The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain Attacks](https://socket.dev/blog/slopsquatting-how-ai-hallucinations-are-fueling-a-new-class-of-supply-chain-attacks)
- [AI Slopsquatting: How LLM Hallucinations Poison Your Code](https://hackernoon.com/ai-slopsquatting-how-llm-hallucinations-poison-your-code)
- [Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code](https://arxiv.org/pdf/2606.13918)
- [Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries](https://arxiv.org/pdf/2509.22202)
- [Slopsquatting: The AI Package Hallucination Attack Already Happening](https://www.aikido.dev/blog/slopsquatting-ai-package-hallucination-attacks)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1187
