DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

AI Coding Agents Exploited via Hallucinated Package Names

Forensic Summary

Researchers from Tel Aviv University, Technion, and Intuit have demonstrated that AI coding agents across tools like Cursor, Copilot, and Gemini CLI predictably hallucinate package, domain, and repository names that attackers can pre-register to deliver malicious code. The attack—variously branded slopsquatting, phantom squatting, and HalluSquatting—requires no phishing, no stolen credentials, and no direct user interaction, only an automated agent with permission to fetch external resources. Because agents handle delivery autonomously and hallucinations are reproducible at up to 100% consistency, the technique scales to botnet-level compromise without traditional malware infrastructure.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/ai-coding-agents-exploited-via-hallucinated-package-names/

Top comments (0)