← All stories
● Covered by 6 sources · 9 reportsMedium impact2 negative

HalluSquatting Attack Exploits AI Hallucinations to Form Botnets

🔄 Updated 29d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • HalluSquatting exploits AI coding assistants' hallucinations.
  • Attackers register fictitious software names to inject malware.
  • Research shows AI hallucination rates of 85% for cloning.
  • AI models' hallucinations undermine user system safety.
  • HalluSquatting can create botnets through fake packages.
  • HalluSquatting exploits LLMs' inability to distinguish legitimate from malicious instructions.
  • Prompt injection attacks are typically 'push' based, targeting individual victims.
  • HalluSquatting is a 'pull-based' attack, where LLMs actively seek adversarial prompts.
  • HalluSquatting can create botnets by tricking AI assistants into running attacker-supplied code.
  • The attack chains two AI quirks: hallucination and indirect prompt injection.
  • HalluSquatting is also called "adversarial hallucination squatting."
  • Researchers from Tel Aviv University, Technion, and Intuit published a paper on HalluSquatting.
  • Hallucination rates reached 100% for skill installations in tests.
  • HalluSquatting is also known as "slopsquatting" and "phantom domains."
  • The research paper on HalluSquatting was published on July 8, 2026.
  • The research team was led by Aya Spira in Ben Nassi's group.

Introduction to HalluSquatting

A new attack method known as HalluSquatting uses AI assistants' hallucinations to register fake software names, enabling the execution of malicious commands. This process can potentially transform compromised AI tools into components of a botnet, threatening large-scale system security.

The term HalluSquatting combines AI's tendency to fabricate information with malicious intent, exploiting AI's vulnerability in distinguishing factual information from invented content.

The Mechanism of HalluSquatting

HalluSquatting relies on AI coding assistants' habit of inventing realistic-sounding but fictitious code repository names. Attackers take advantage of this by registering these names and using them to distribute malware.

The method utilizes AI hallucinations, where the AI generates a non-existent resource name, misdirecting the system to execute harmful instructions when these resources are retrieved—laying the groundwork for potential botnets.

Research Findings and Implications

Conducted by researchers from Tel Aviv University and others, the study shows hallucination rates as high as 85% for certain tasks, indicating the widespread potential of these attacks.

By exploiting AI's predictable way of generating repository URLs and other resources, attackers can scale up the attack across multiple systems, underlining a significant new vector in cybersecurity threats.

Why HalluSquatting Matters

HalluSquatting exemplifies a fundamental vulnerability in AI coding tools, highlighting critical issues in AI safety and security protocols.

The ability to generate botnets from AI hallucinations presents long-term risks to user systems and broader network security, emphasizing the need for improved measures to distinguish between legitimate and fictitious content in AI operations.

Updates

🕒 2026-07-24 · new reporting from BleepingComputer
  • HalluSquatting exploits LLMs' inability to distinguish legitimate from malicious instructions.
  • Prompt injection attacks are typically 'push' based, targeting individual victims.
  • HalluSquatting is a 'pull-based' attack, where LLMs actively seek adversarial prompts.
  • HalluSquatting can create botnets by tricking AI assistants into running attacker-supplied code.
  • The attack chains two AI quirks: hallucination and indirect prompt injection.
  • HalluSquatting is also called "adversarial hallucination squatting."
  • Researchers from Tel Aviv University, Technion, and Intuit published a paper on HalluSquatting.
  • Hallucination rates reached 100% for skill installations in tests.
  • HalluSquatting is also known as "slopsquatting" and "phantom domains."
  • The research paper on HalluSquatting was published on July 8, 2026.
  • The research team was led by Aya Spira in Ben Nassi's group.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A new prompt injection technique, termed "AI Recommendation Poisoning," is being used on commercial websites to bias large language models (LLMs) by embedding hidden payloads in "Ask AI" buttons. These payloads, delivered via deep links, instruct LLMs to permanently save specific domains as trusted sources, influencing future AI responses. This method bypasses traditional defenses and was cataloged by Microsoft Security in February 2026, affecting 31 companies across 14 industries.

Researchers have identified a critical vulnerability in AI coding agents where they treat hallucinated identifiers as verified commands, leading to scalable supply chain attacks. This flaw, termed HalluSquatting, allows attackers to pre-register non-existent names that AI models generate, enabling the delivery of malicious code without direct user interaction or traditional compromise methods.

Intruder has developed an AI-powered vulnerability scanning pipeline that autonomously discovers and exploits security flaws, including a zero-day in a WordPress plugin. This automation enables faster vulnerability identification with no human intervention, which streamlines the process for software developers.

Researchers from Tracebit discovered that prompt injections can effectively secure AI platforms by shutting down malicious actions. By embedding forbidden commands alongside sensitive data in AWS, they found this technique, termed context bombing, significantly reduced successful exploits from AI attackers.

Slopsquatting is a new supply chain threat exploiting AI coding assistants' hallucinations to inject malicious code. This attack exploits fictitious package names generated by AI, allowing cybercriminals to register and distribute malware through legitimate development workflows.

Researchers introduced 'HalluSquatting', exploiting AI hallucinations to create a botnet delivery method. This technique allows attackers to pre-register fake resource names, leading to widespread malware deployment via compromised AI tools.

The HalluSquatting attack, detailed in a study from Tel Aviv University and others, exploits AI's tendency to hallucinate incorrect responses. This vulnerability allows attackers to trick AI agents into executing malicious code, potentially compromising user systems.

Research has revealed a new attack called HalluSquatting that exploits AI coding assistants' tendency to generate fictitious names. By registering these fake names, attackers can trick AI assistants into executing malicious commands, potentially forming a botnet.

Researchers identified a new attack method called HalluSquatting, which exploits large language models (LLMs) used in AI coding assistants. This technique can potentially assemble massive botnets and conduct large-scale attacks by injecting malicious commands through hallucinated code identifiers.