Tools AI Risk Radar ai-incident-0061
Incident record
HalluSquatting: attackers register the names AI assistants invent
- Severity
- Medium
- Status
- Research
- Type
- Poisoning
- Target
- AI coding assistants
- Actor
- researcher
What happened
Researchers at Tel Aviv University, the Technion and Intuit, with Aya Spira as first author and Ben Nassi as senior author, described adversarial hallucination squatting, or HalluSquatting: agentic coding assistants repeatedly invent the same non-existent resource names, chiefly GitHub repository slugs and agent skill names, and an attacker can register those names in advance and host a prompt-injection payload there. Hallucination rates ran up to 85 per cent for repository cloning and up to 100 per cent for skill installation, and the team reached remote tool execution and remote code execution against Cursor, Cursor CLI, Gemini CLI, Windsurf, Copilot Chat, Cline and the OpenClaw, NanoClaw and ZeroClaw assistants.
Under instruction from their ethics board the team registered a benign GitHub repository and published a benign skill, kept the repository private between experiments and deleted it afterwards, and ran the code-execution payloads only on their own machine. They disclosed to Google, Cline, Cursor and GitHub. Separately, Charlie Eriksen of Aikido Security found react-codeshift, a name a language model invented by conflating jscodeshift and react-codemod, referenced by 237 GitHub repositories that instructed agents to install it; he registered the name himself on 14 January 2026. The paper does not cover that case. arXiv 2607.07433 is a preprint with no peer-reviewed venue named.
Sources
- Spira and others: beware of agentic botnets, scalable untargeted promptware attacks via adversarial HalluSquatting (arXiv 2607.07433, 8 July 2026)arxiv.org/abs/2607.07433
- Beware of agentic botnets: the full textarxiv.org/html/2607.07433v1
- The agentic botnets project sitesites.google.com/view/agentic-botnets/home
- Aikido Security: agent skills are spreading hallucinated npx commands (21 January 2026)www.aikido.dev/blog/agent-skills-spreading-hallucinated-npx-…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026