Threat · curated 19 Jul 2026
HalluSquatting attack exploits AI hallucinations to spread malware
First reported foxnews.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
HalluSquatting turns predictable LLM hallucinations into a software supply-chain vector, meaning developers relying on AI coding assistants can be steered into pulling malicious packages without any traditional social engineering.
The HalluSquatting attack exploits AI hallucinations by registering package or software names that large language models invent when suggesting dependencies, so developers who trust AI-recommended names end up installing attacker-controlled malware. The technique weaponizes the tendency of LLMs to hallucinate plausible-sounding but nonexistent package names.