Cyber Security Published on July 10, 2026
HalluSquatting turns AI hallucinations into botnet delivery mechanism
Researchers disclosed HalluSquatting, an untargeted promptware technique that exploits the predictable way LLMs hallucinate package or repository names.
Attackers pre-register the fake names, seed them with malicious instructions, and wait for AI assistants such as Cursor, Windsurf, GitHub Copilot, Cline, and Gemini CLI to fetch and execute them.
Tests reported hallucination rates up to 85% for repository-cloning prompts and 100% for skill installations, creating a scalable path to agentic botnets.