Researchers disclosed HalluSquatting, a prompt-injection technique that abuses AI coding assistants' tendency to hallucinate package, repository, plugin, or registry names and then retrieve them automatically. By predicting the fake identifiers a model is likely to invent, attackers can register those names on services such as GitHub or plugin stores, seed them with malicious instructions or payloads, and induce the assistant to execute attacker-controlled code. The researchers reported highly repeatable hallucinations—reaching up to 85% for repository requests and 100% for some skill-install scenarios—and said the method can deliver reverse shells and other malware without relying on software exploits, worms, or stolen credentials.
The attack was reported to affect tools including Cursor, Cursor CLI, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw, and NanoClaw, many of which can fetch third-party resources and run with elevated command-line privileges. Researchers from Tel Aviv University, Technion, and Intuit said they disclosed the issue to vendors while withholding full reproduction details, warning that the technique could enable large-scale device compromise, botnet assembly, and DDoS activity across mixed environments. Recommended defenses include forcing assistants to search and verify resources before fetching them, validating package and repository names, disabling unattended auto-run behavior, and having platforms reserve likely hallucinated identifiers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The researchers said they disclosed the HalluSquatting issue to affected vendors and withheld exact reproduction details. The disclosure accompanied recommendations such as verifying resources before fetching them, disabling unattended auto-run modes, and reserving likely hallucinated names on platforms.
Researchers from Tel Aviv University, Technion, and Intuit described HalluSquatting, a prompt-injection technique that exploits AI assistants' tendency to hallucinate package, repository, or plugin names and then fetch attacker-controlled resources. They demonstrated code execution against multiple coding assistants and characterized the technique as a scalable path to mass compromise and botnet assembly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcezdnet.fr
Open sourcesocradar.io
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcearstechnica.com
Open sourcesites.google.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.