
New 'HalluSquatting' Attack Exploits AI Coding Assistants to Distribute Malware
AI SecuritySupply-Chain AttacksMalware DistributionAI Vulnerabilities
Researchers have identified a new attack method called 'HalluSquatting,' which exploits AI coding assistants' tendency to generate plausible but nonexistent tool or package names. Attackers preemptively register these hallucinated names as malicious packages, tricking AI assistants into recommending them to users. The technique leverages the assistants' reliance on fabricated yet convincing project names to distribute malware, potentially leading to botnet infections. No specific AI tools, malware samples, or affected systems were named in the report. The research highlights a novel supply-chain risk tied to AI-generated recommendations in development environments.