HalluSquatting , and Intuit have just revealed, and it promises to turn the most popular AI coding assistants into automatic distributors of malicious code. The study, published on July 9, 2026 on arXiv, shows that tools like Cursor, GitHub Copilot, Gemini CLI, Windsurf, and Cline are being tricked by unsuspecting developers into pulling malicious repositories with success rates reaching 85% for repository cloning and 100% for skill installation.

The HalluSquatting technique — also called adversarial hallucination squatting— exploits a fundamental weakness of large language models: when developers ask an AI coding assistant to download a trending repository or install a specialized library, the model often comes up with names that sound logical but don’t actually exist. The attacker doesn’t need to target any victims — he simply guesses which names the model will “dream up” and registers them with malicious content in time.
The mechanism of the HalluSquatting attack
The HalluSquatting attack chain involves five steps, mechanically simple but devastatingly effective, as described in the DEV Community. First, the attacker identifies a popular repository or skill that has emerged in recent months — new enough that it is not fully included in the models’ training data.
Second, it asks the models with a series of prompts like “clone this repository” or “install this skill” and records which name variations they end up with. Third, it identifies one or more persistent hallucinations — names that appear repeatedly and in different models. Fourth, it registers those names on GitHub, PyPI, npm, or skill stores, loading them with a reverse shell, downloader, or other malicious payload. Fifth and final step, it waits: every time a developer asks its AI to download the initial dependency, the AI “sees” the trap and executes the malicious code with the user’s privileges.
See also: GhostApproval: Symlink vulnerabilities in 6 AI coding assistants
Which tools does it affect?
The list of tools that have been confirmed to be affected is impressively long and includes almost every mainstream AI coding assistant. According to Tom's Hardware, the researchers achieved successful remote code execution or tool invocation in: Cursor, Cursor CLI, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw , and NanoClaw.
The rates vary by product. For coding assistants like Cursor, Gemini CLI, and Copilot, the success rates for hacking are in the 20% to 35%. For OpenClaw, ZeroClaw, and NanoClaw, the corresponding success rates jump to between 80% and 100%. At the model level, the average hallucination rate for recently trending repositories is 92.4%, a number that even includes Anthropic's top-of-the-line Claude Opus 4.5.

How does it differ from classic typosquatting?
Classic typosquatting requires the attacker to predict what a human might type incorrectly. The HalluSquatting attack completely reverses the paradigm: the attacker does not target the human, but the statistical behavior of the model. The researchers document that when a prompt that induces a hallucination is repeated, the same invented name appears in 43% of trials, while 58% of hallucinations are repeated in independent sessions. It is this repeatability that gives the attacker an advantage.
The most worrying finding, however, is not just repeatability — it’s transferability. The researchers showed that persistent hallucinations are transferable between different foundational models and from the model level to the application level. A malicious name registered based on GPT-5 behavior has a high probability of being “pulled” by both Claude and Gemini, and any production tool based on them. A registered malicious repository can potentially infect tens of thousands of bots at once, paving the way for truly botnet-scale attacks.
See also: Friendly Fire: AI agents are tricked into executing malicious code
The real threat: HalluSquatting as a botnet framework
The researchers don't stop at proof-of-concept. In the published paper, they present HalluSquatting as a mechanism for mass botnet formation: a single registered malicious repository can act as a point of infection for every machine running an agentic LLM application and "pulling" the same hallucinated name.
The HalluSquatting attack is powered by two elements: the selection of popular trending resources —which ensures a high volume of queries to the AI tools— and the identification of the most likely hallucinations of each model. The combination of these two means that an attacker can infect “n” machines with “1” malicious resource, where n depends solely on the popularity of the original resource and not on the attacker’s effort. It is, in other words, one of the most asymmetric attack scenarios ever recorded in the software supply chain.

Examples already "in nature"
Researchers at Forbes Tech Council document that the phenomenon is no longer theoretical: in January 2026, the fictional react-codeshift was propagated to 237 repositories via 47 agent skill files without any human oversight. Recent research identified 127 packages (109 on PyPI, 18 on npm) that are consistently produced as hallucinations by all major frontier models.
A Usenix Security 2025 analysis of 576,000 samples from 16 models found that commercial models are affected by 5.2%, while open-source models are affected by 21.7%. And according to Sonatype, nearly 8% of dependency suggestions from top LLMs over a three-month period were for nonexistent versions — errors that, if reported in time by malicious actors, would have infected countless projects.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
How to protect yourself from HalluSquatting attacks
The SecNews technical team suggests five practical defense measures. First and foremost: do not allow the AI agent to perform installations or clones without an intermediate verification step. A script that does a pre-install existence check and registry API check is enough to prevent most HalluSquatting scenarios.
Second measure: mandatory web search before each install. The researchers themselves show that when assistants are forced to confirm the existence of a resource through a search before downloading it, the rates of successful HalluSquatting drop dramatically.
Third: disable auto-run behavior in unattended workflows. A human reviewing each install command reduces step (5) of the HalluSquatting chain to almost zero. Fourth: packaging registries like GitHub, PyPI, and npm to proactively reserve high-probability hallucinated names as neutral (defensive squatting), removing the “battlefield” from attackers. Fifth measure: use trust-score tools like SlopScan or equivalent supply-chain guards that check existence, age, downloads, and reputation before any install command is executed.
See also: SymJack: New attack turns AI coding agents into supply chain weapons
HalluSquatting highlights a fundamental truth for the era of agentic AI applications: security can no longer rely solely on human vigilance, nor solely on the quality of the model. An intermediate layer of verification is needed—packaging registry checks, trust scoring, mandatory web verification—that intervenes between the “suggestion” of the model and the “execution” of the command. Without this layer, any mass adoption of agentic coding assistants automatically translates into a massive expansion of the attack surface—and into a truly new kind of botnet that doesn’t even need to target its victims.
