Research · curated 25 Jul 2026
HalluSquatting AI attack could hijack your computer
First reported aol.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
HalluSquatting turns predictable LLM hallucinations into a software supply-chain attack vector against AI agents that autonomously fetch and execute code, exposing developers and users to attacker-controlled repositories.
HalluSquatting is a technique detailed by researchers from Tel Aviv University, Technion, and Intuit in which attackers exploit AI coding assistants and browsing agents that hallucinate software repository names. By repeatedly prompting models to locate popular projects, attackers discover consistently invented (fake) repo/package names, register them, and plant malicious instructions so an AI agent that retrieves and runs the files can deliver malware, steal data, or recruit the device into a botnet.