Researchers from Tel Aviv University, Technion, and Intuit have unveiled a novel attack technique called HalluSquatting that weaponizes one of AI's most familiar flaws — the tendency to make things up — into a scalable infection vector.

Unlike traditional prompt injection, which requires a direct channel to the targeted AI, HalluSquatting is an untargeted attack that exploits AI at scale without any direct communication. Here's how it works:

1. **Pick a trending target.** The attacker finds a popular repository or plugin that users frequently ask AI assistants to fetch. Since brand-new resources aren't in training data, models start guessing names. 2. **Learn the hallucination.** The attacker queries the AI repeatedly and records the fake name it invents most consistently. 3. **Register the fake name.** The attacker claims that name on GitHub or a plugin marketplace, hiding adversarial instructions inside. 4. **Wait.** When a real user asks their assistant to fetch the popular resource, the assistant hallucinates the squatted name, pulls in the attacker's version, and executes its hidden commands.

**The numbers are alarming. In tests, hallucination rates reached 85% for repository-cloning prompts and 100% for skill installations** — and the same fake names recurred across different foundation models, making the technique broadly transferable.

Affected tools include Cursor, Windsurf, GitHub Copilot, Cline, Google's Gemini CLI, and the OpenClaw family of assistants. Researchers demonstrated that each could be tricked into running attacker-supplied code on the machine.

The attack creates what researchers call "agentic botnets" — botnets assembled not through traditional vulnerabilities or weak passwords, but through prompt injections that bypass firewalls and can take root on virtually any device. Unlike traditional botnets (like Mirai, which herded cameras and routers), these botnets can span any operating system.

Mitigation centers on one condition: AI agents that fetch and run external resources without human review. The simplest fix is making assistants search before they fetch — grounding the agent in what actually exists. Users should avoid auto-run modes (like Gemini CLI's "yolo mode" or Claude Code's skip-permissions flag) and treat any name an AI produces as a guess until verified.

Researchers notified affected vendors before publication and withheld the most dangerous exploit details. As the team noted: "Attacks always get better; they never get worse." The vulnerability isn't a single CVE — it's a design flaw in how AI agents trust names they were never actually given.