YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0061

Incident record

HalluSquatting: attackers register the names AI assistants invent

Severity
Medium
Status
Research
Type
Poisoning
Target
AI coding assistants
Actor
researcher

What happened

Researchers at Tel Aviv University, the Technion and Intuit, with Aya Spira as first author and Ben Nassi as senior author, described adversarial hallucination squatting, or HalluSquatting: agentic coding assistants repeatedly invent the same non-existent resource names, chiefly GitHub repository slugs and agent skill names, and an attacker can register those names in advance and host a prompt-injection payload there. Hallucination rates ran up to 85 per cent for repository cloning and up to 100 per cent for skill installation, and the team reached remote tool execution and remote code execution against Cursor, Cursor CLI, Gemini CLI, Windsurf, Copilot Chat, Cline and the OpenClaw, NanoClaw and ZeroClaw assistants.

Under instruction from their ethics board the team registered a benign GitHub repository and published a benign skill, kept the repository private between experiments and deleted it afterwards, and ran the code-execution payloads only on their own machine. They disclosed to Google, Cline, Cursor and GitHub. Separately, Charlie Eriksen of Aikido Security found react-codeshift, a name a language model invented by conflating jscodeshift and react-codemod, referenced by 237 GitHub repositories that instructed agents to install it; he registered the name himself on 14 January 2026. The paper does not cover that case. arXiv 2607.07433 is a preprint with no peer-reviewed venue named.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026