‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism

A New Attack Vector Emerges: ‘HalluSquatting’ Turns AI Hallucinations into Botnet Delivery Mechanism

Researchers have uncovered a novel attack technique that exploits the tendency of artificial intelligence (AI) assistants to “hallucinate” or generate false information. Dubbed “HalluSquatting,” this method leverages the ability of AI tools to create fake resources and packages, allowing attackers to create a scalable infection vector without direct access to the target device.

The technique relies on a process called adversarial hallucination squatting, where threat actors pre-register fake repository or package names that AI applications commonly invent when asked to fetch popular or trending resources. The research team found that in their tests, hallucination rates reached as high as 85% for repo-cloning prompts and 100% for skill installations.

Once the attacker has registered these squatted names, they can plant malicious instructions inside them. When an unsuspecting user asks an AI tool to clone a repository or install a skill, it may hallucinate the squatted name, pull it down, and execute the attacker’s commands via its built-in terminal. These commands can then direct the AI to run additional tools or code, potentially deploying malware or hacking tools.

The HalluSquatting technique has significant implications for cybersecurity, as it allows attackers to create agentic botnets that spread through prompt injections, bypassing traditional firewalls and taking root on virtually any device. This results in a more heterogeneous population of compromised hosts than traditional botnets.

Researchers have warned vendors affected by this attack vector, and they have withheld exploit details that could be directly reused by attackers. The technique’s reliance on AI hallucinations means that it can be used to compromise devices without a direct channel or vulnerability, making it a particularly insidious threat.

The emergence of HalluSquatting highlights the need for improved security measures around AI tools and applications. As AI continues to play an increasingly important role in our lives, it’s essential to recognize the potential risks associated with its use and develop strategies to mitigate them.

In practical terms, users should be cautious when interacting with AI assistants and ensure that they are using reputable tools and services. Additionally, developers of AI applications should prioritize implementing robust security measures to prevent such attacks from succeeding. By taking these precautions, we can reduce the risk of HalluSquatting-style attacks and protect ourselves against this emerging threat vector.


Source: SecurityWeek — 2026-07-10