The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers from Tel Aviv University, Technion, and Intuit have shown that AI coding agents like Cursor, GitHub Copilot, and Gemini CLI can be hijacked through so-called HalluSquatting attacks, where attackers pre-register package, domain, or repository names that AI models predictably hallucinate.
- The agents then fetch and execute malicious code from these fake sources without verification, effectively giving attackers a way to distribute malware at scale without phishing or stolen passwords.
- This is the third such attack in six months, following slopsquatting and phantom squatting, and the report says current security tools fail against these patterns.
- The risk is amplified because agents often run with broad permissions and because compromised transitive dependencies deep in a project's tree can go uninspected.
What to watch next
- Whether AI coding agent vendors add verification or governed catalogs before agents fetch hallucinated names.
- How security tooling evolves to check transitive dependencies and agent skill stores, given the noted Trail of Bits scanner bypass.
- Whether new variants of these name-squatting attacks emerge, since researchers say their findings are a floor, not a ceiling.
Coverage1
1 report
International1
All filed from United States
Named Israel · United States · Cline · Cursor · Gemini CLI · GitHub Copilot · npm · OpenClaw · Windsurf · ActiveState · ActiveState Curated Catalog · Aya Spira · Ben Nassi · Intuit
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
