Threat reportSupply ChainTL-2026-1671
HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting Attacks
HalluSquatting (TL-2026-1671), also tracked as HalluSquatting, is a high-severity supply-chain compromise, first published 2026-07-24. It has no confirmed attribution, affects Multiple AI Coding Agents (Cursor, Cursor CLI, Windsurf, GitHub, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1671
- Threat ID
- TL-2026-1671
- Also known as
- HalluSquatting, Slopsquatting, Phantom Squatting
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, health, ecommerce, government administration, gambling, logistics
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in HalluSquatting
Malware and tooling: Agentic botnet installer, Cisco skill-scanner
How HalluSquatting works
Researchers from Tel Aviv University, Technion, and Intuit show that nine popular AI coding agents (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, NanoClaw) hallucinate the same fake repository, package, and skill names at high, predictable rates -- up to 85% for repository-clone requests and up to 100% for skill installs -- letting attackers pre-register those exact names to serve malware and build agentic botnets. HalluSquatting generalizes two earlier real-world incidents: slopsquatting (the react-codeshift fake npm package that reached 237 projects, Jan 2026) and phantom domain squatting (~250,000 unregistered hallucinated brand domains discovered by Unit 42, Jun 2026).
HalluSquatting, formally described in the paper "Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting" (arXiv:2607.07433, published 2026-07-08) by Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi (Tel Aviv University, Technion, Intuit), identifies a systemic root cause behind three previously siloed AI-supply-chain incidents: LLM-backed coding agents generate probabilistic text that is predictable enough to precompute, and agent runtimes execute that text (clone a repo, install a package, install a skill) before any vetting or verification of the resource's authenticity -- a pattern the researchers call 'late-binding execution.'
The attack chain: (1) an attacker identifies a trending resource (a popular repository, npm package, or agent skill) that developers frequently ask AI assistants to fetch; (2) the attacker probes multiple LLMs and prompt phrasings to find the resource name(s) the models hallucinate most consistently -- across different models and phrasings, the same wrong name recurred in up to 85% of repository requests and 100% of skill-install requests; (3) the attacker pre-registers that exact hallucinated name on GitHub, npm, or a skill marketplace (ClawHub, Cisco's skill-scanner-fronted store, skills.sh) with an embedded adversarial/malicious payload or indirect prompt injection; (4) when a legitimate developer later asks their AI agent to fetch the real resource, the agent hallucinates the same wrong name and the agent's own terminal-execution tool installs and runs the attacker's payload -- typically enrolling the developer's machine into a botnet usable for cryptomining, DDoS, or as a foothold for further lateral compromise across networks the developer can reach. No exploit of the underlying OS or network stack is required; the AI agent's legitimate command-execution capability is the delivery mechanism.
The research explicitly ties HalluSquatting to two precedent incidents that motivated it: (a) Slopsquatting -- in January 2026, Aikido Security researcher Charlie Eriksen discovered 'react-codeshift', a hallucinated mash-up of the real packages jscodeshift and react-codemod, that had propagated via a single unreviewed AI-generated commit into 237 downstream repositories (via forks and translation) and was still receiving daily install attempts from autonomous agents; Eriksen defensively registered the name himself to prevent exploitation. (b) Phantom (domain) Squatting -- Unit 42 (Palo Alto Networks) ran a multi-agent adversarial-prompting pipeline across 913 global brands and 685,339 prompts against two LLM families, generating 2.1 million candidate URLs, of which 809,455 resolved to non-existent domains and roughly 250,000 remained unregistered and available for adversarial claiming; 13,229 of the generated URLs were already independently flagged as malicious. Confirmed hallucinated-domain abuse split 67.2% malware delivery, 16.2% phishing, 13.7% grayware, 3.0% C2 infrastructure, and documented real cases include a postal-service e-commerce phishing kit (23-day lead time between hallucination detection and attacker registration) and an Android malware (.apk) landing page (51-day lead time) targeting brand-impersonation victims.
A third, adjacent finding underlines that defenses are currently inadequate: Trail of Bits ('The Sorry State of Skill Distribution', 2026-06-03) bypassed every public AI-agent-skill scanner it tested (ClawHub's VirusTotal+LLM-guard pipeline, Cisco's skill-scanner, and all three scanners wired into skills.sh) in under an hour using trivial techniques -- prepending 100,000 blank lines to truncate scanner analysis before the payload, hiding logic in binary/archive formats, and prompt-injecting the scanner's own LLM judge. A related fake skill reportedly passed every scanner and reached roughly 26,000 agent installs before detection, underscoring that current skill-store vetting checks a fixed artifact once while an attacker can iterate the payload until it passes.
Mitigations recommended across the disclosing researchers and downstream coverage center on closing the late-binding gap: enable pre-fetch/pre-install verification against real, ground-truth catalogs (disabled by default in most agent frameworks today); route dependency and skill resolution through vetted/curated catalogs rather than raw web/registry lookups; treat AI-suggested repository, package, and skill names as unverified guesses, not facts, requiring human or automated confirmation before execution; disable blanket auto-run/auto-approve modes (e.g., Claude's skip-permissions flag, Gemini CLI's YOLO mode) in agent configurations; and, at the platform level, defensively pre-register predictably-hallucinated names (as Aikido did with react-codeshift) and prevent name-squatting/reuse of well-known repository and package identifiers under new accounts.
MITRE ATT&CK techniques used in TL-2026-1671
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Credential Access
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Persistence
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Impact
T1496 Resource Hijacking; T1498 Network Denial of Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1608 Stage Capabilities
Reconnaissance
Affected products and versions in HalluSquatting
- Multiple — AI Coding Agents (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, OpenClaw, ZeroClaw, NanoClaw)
Vulnerable versions: all versions tested by researchers as of 2026-07-08
Fixed in: no universal patch; mitigated by pre-fetch verification and disabling auto-run modes - npm / GitHub / AI skill marketplaces — Public package registries, repository hosting, and agent-skill stores (npm registry, GitHub, ClawHub, Cisco skill-scanner store, skills.sh)
Vulnerable versions: current registration and scanning processes as of 2026-07
Fixed in: none reported; scanners bypassed by Trail of Bits in under one hour
Remediation for HalluSquatting
Immediate actions
- Disable blanket auto-run/auto-approve agent modes (e.g., skip-permissions flags, Gemini CLI YOLO mode) so repository, package, and skill fetch/install actions require human confirmation
- Treat every AI-suggested repository URL, package name, or skill name as an unverified claim -- manually resolve and confirm it against the real, canonical source before allowing the agent to fetch or execute it
- Audit recent agent-driven installs/clones in CI and developer environments for names that do not match known-good canonical repositories or packages
- Defensively pre-register organization-adjacent names that AI agents are observed hallucinating (mirrors Aikido Security's react-codeshift defensive registration)
Workarounds
- Pin explicit, verified repository/package/skill identifiers in project configuration rather than letting agents resolve names dynamically
- Restrict AI coding agent terminal/command-execution capability via sandboxing or allow-listed command sets
Longer-term hardening
- Route all agent-initiated dependency, repository, and skill resolution through a vetted/curated internal catalog instead of raw web search or public registry lookups
- Require pre-fetch verification (existence, ownership, provenance, signature) before any agent is permitted to execute code from a newly-referenced resource
- Do not rely on skill-store or package-registry scanners as a sole control -- assume they can be bypassed via truncation padding, binary/archive-hidden logic, or judge-model prompt injection
- Adopt AI-runtime/agentic security monitoring (e.g., AI Security Assessment tooling, agent endpoint security) to detect anomalous terminal command execution originating from coding-agent sessions
Weaknesses (CWE) in HalluSquatting
Timeline of HalluSquatting
- Aikido Security researcher Charlie Eriksen discovers 'react-codeshift', a hallucinated npm package (mash-up of jscodeshift and react-codemod) already propagated into 237 downstream repositories via AI-generated agent skill files; he defensively registers the name to prevent hostile takeover.
- Unit 42's hallucination-monitoring pipeline flags a domain resembling a national postal service's e-commerce marketplace as a high-persistence hallucination target ('Montana Empire' case).
- An adversary registers the exact domain Unit 42 had flagged 23 days earlier and stands up a fully functional phishing operation impersonating the postal service marketplace.
- A fake AI-agent skill is reported to have passed every public skill-store security scanner and reached roughly 26,000 agent installs before detection.
- Unit 42 (Palo Alto Networks) publishes 'Phantom Squatting' research: across 913 brands and 685,339 adversarial prompts, ~250,000 hallucinated brand domains remain unregistered and available for adversarial claiming.
- Trail of Bits publishes 'The Sorry State of Skill Distribution', demonstrating bypass of every tested skill-store scanner (ClawHub, Cisco skill-scanner, skills.sh) in under one hour via truncation padding, binary-hidden logic, and judge-model prompt injection.
- Vendors of the affected AI coding agents (Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw family) are notified under responsible disclosure prior to publication; researchers withhold full exploitation payload details.
- Tel Aviv University, Technion, and Intuit researchers (Spira, Cohen, Feldman, Bitton, Wool, Nassi) publish 'Beware of Agentic Botnets' (arXiv:2607.07433), formally naming and quantifying HalluSquatting across nine AI coding agents, unifying it with slopsquatting and phantom squatting as instances of the same late-binding-execution root cause.
- BleepingComputer publishes a synthesis piece explicitly connecting slopsquatting, phantom domains, and HalluSquatting as three manifestations of one systemic AI-agent supply-chain attack pattern.
Sources cited for HalluSquatting
- Slopsquatting, phantom domains, and HalluSquatting are the same AI attack
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
- Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
- New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
- The sorry state of skill distribution
- Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
- Slopsquatting: The AI Package Hallucination Attack Already Happening
- 'HalluSquatting' Compromises AI Coding Agents to Install Malware, Create Botnets
- HalluSquatting attack exploits AI hallucinations to spread malware
Detection coverage for TL-2026-1671
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1671 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.