# HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting Attacks

> Researchers from Tel Aviv University, Technion, and Intuit show that nine popular AI coding agents (Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline, Gemini CLI, OpenClaw, ZeroClaw, NanoClaw) hallucinate the same fake repository, package, and skill names at high, predictable rates -- up to 85% for repository-clone requests and up to 100% for skill installs -- letting attackers pre-register those exact names to serve malware and build agentic botnets. HalluSquatting generalizes two earlier real-world incidents: slopsquatting (the react-codeshift fake npm package that reached 237 projects, Jan 2026) and phantom domain squatting (~250,000 unregistered hallucinated brand domains discovered by Unit 42, Jun 2026).

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1671
- **ID:** TL-2026-1671
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

HalluSquatting, formally described in the paper "Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting" (arXiv:2607.07433, published 2026-07-08) by Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi (Tel Aviv University, Technion, Intuit), identifies a systemic root cause behind three previously siloed AI-supply-chain incidents: LLM-backed coding agents generate probabilistic text that is predictable enough to precompute, and agent runtimes execute that text (clone a repo, install a package, install a skill) before any vetting or verification of the resource's authenticity -- a pattern the researchers call 'late-binding execution.'

The attack chain: (1) an attacker identifies a trending resource (a popular repository, npm package, or agent skill) that developers frequently ask AI assistants to fetch; (2) the attacker probes multiple LLMs and prompt phrasings to find the resource name(s) the models hallucinate most consistently -- across different models and phrasings, the same wrong name recurred in up to 85% of repository requests and 100% of skill-install requests; (3) the attacker pre-registers that exact hallucinated name on GitHub, npm, or a skill marketplace (ClawHub, Cisco's skill-scanner-fronted store, skills.sh) with an embedded adversarial/malicious payload or indirect prompt injection; (4) when a legitimate developer later asks their AI agent to fetch the real resource, the agent hallucinates the same wrong name and the agent's own terminal-execution tool installs and runs the attacker's payload -- typically enrolling the developer's machine into a botnet usable for cryptomining, DDoS, or as a foothold for further lateral compromise across networks the developer can reach. No exploit of the underlying OS or network stack is required; the AI agent's legitimate command-execution capability is the delivery mechanism.

The research explicitly ties HalluSquatting to two precedent incidents that motivated it: (a) Slopsquatting -- in January 2026, Aikido Security researcher Charlie Eriksen discovered 'react-codeshift', a hallucinated mash-up of the real packages jscodeshift and react-codemod, that had propagated via a single unreviewed AI-generated commit into 237 downstream repositories (via forks and translation) and was still receiving daily install attempts from autonomous agents; Eriksen defensively registered the name himself to prevent exploitation. (b) Phantom (domain) Squatting -- Unit 42 (Palo Alto Networks) ran a multi-agent adversarial-prompting pipeline across 913 global brands and 685,339 prompts against two LLM families, generating 2.1 million candidate URLs, of which 809,455 resolved to non-existent domains and roughly 250,000 remained unregistered and available for adversarial claiming; 13,229 of the generated URLs were already independently flagged as malicious. Confirmed hallucinated-domain abuse split 67.2% malware delivery, 16.2% phishing, 13.7% grayware, 3.0% C2 infrastructure, and documented real cases include a postal-service e-commerce phishing kit (23-day lead time between hallucination detection and attacker registration) and an Android malware (.apk) landing page (51-day lead time) targeting brand-impersonation victims.

A third, adjacent finding underlines that defenses are currently inadequate: Trail of Bits ('The Sorry State of Skill Distribution', 2026-06-03) bypassed every public AI-agent-skill scanner it tested (ClawHub's VirusTotal+LLM-guard pipeline, Cisco's skill-scanner, and all three scanners wired into skills.sh) in under an hour using trivial techniques -- prepending 100,000 blank lines to truncate scanner analysis before the payload, hiding logic in binary/archive formats, and prompt-injecting the scanner's own LLM judge. A related fake skill reportedly passed every scanner and reached roughly 26,000 agent installs before detection, underscoring that current skill-store vetting checks a fixed artifact once while an attacker can iterate the payload until it passes.

Mitigations recommended across the disclosing researchers and downstream coverage center on closing the late-binding gap: enable pre-fetch/pre-install verification against real, ground-truth catalogs (disabled by default in most agent frameworks today); route dependency and skill resolution through vetted/curated catalogs rather than raw web/registry lookups; treat AI-suggested repository, package, and skill names as unverified guesses, not facts, requiring human or automated confirmation before execution; disable blanket auto-run/auto-approve modes (e.g., Claude's skip-permissions flag, Gemini CLI's YOLO mode) in agent configurations; and, at the platform level, defensively pre-register predictably-hallucinated names (as Aikido did with react-codeshift) and prevent name-squatting/reuse of well-known repository and package identifiers under new accounts.

## MITRE ATT&CK

- T1593 Search Open Websites/Domains
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1136 Create Account
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1056 Input Capture
- T1102 Web Service
- T1071 Application Layer Protocol
- T1496 Resource Hijacking
- T1498 Network Denial of Service

## Sources

- [Slopsquatting, phantom domains, and HalluSquatting are the same AI attack](https://www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/)
- [New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware](https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html)
- [Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting](https://arxiv.org/abs/2607.07433)
- [New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware](https://cybersecuritynews.com/hallusquatting-attack-poison-ai-coding-assistants/)
- [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/)
- [The sorry state of skill distribution](https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/)
- [Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents](https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html)
- [Slopsquatting: The AI Package Hallucination Attack Already Happening](https://www.aikido.dev/blog/slopsquatting-ai-package-hallucination-attacks)
- ['HalluSquatting' Compromises AI Coding Agents to Install Malware, Create Botnets](https://devops.com/hallusquatting-compromises-ai-coding-agents-to-install-malware-create-botnets/)
- [HalluSquatting attack exploits AI hallucinations to spread malware](https://www.foxnews.com/tech/hallusquatting-ai-attack-could-hijack-your-computer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1671
