Alex Yao Alex Yao
Back to news
Cyber Security Published on July 10, 2026

HalluSquatting turns AI hallucinations into botnet delivery mechanism

Researchers disclosed HalluSquatting, an untargeted promptware technique that exploits the predictable way LLMs hallucinate package or repository names.

Attackers pre-register the fake names, seed them with malicious instructions, and wait for AI assistants such as Cursor, Windsurf, GitHub Copilot, Cline, and Gemini CLI to fetch and execute them.

Tests reported hallucination rates up to 85% for repository-cloning prompts and 100% for skill installations, creating a scalable path to agentic botnets.