news.mlab.sh
Back to the feed
threat-intel

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

Medium
Image: The Hacker News
Summary

Researchers at Tel Aviv University have identified a new attack method called ‘HalluSquatting’ that leverages AI coding assistants’ tendency to fabricate names. Attackers register fake software package names that AIs commonly invent, then trick the assistants into fetching these fabricated resources, which then execute attacker-supplied code. This bypasses traditional security measures as the payload arrives as text, not a network exploit, and can be used to assemble a botnet across diverse operating systems. The attack relies on a combination of AI hallucination and prompt injection, and has been successfully demonstrated against tools like GitHub Copilot, Gemini, and OpenClaw assistants.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.