Back Feeds.4Sysops HalluSquatting attack weaponizes AI hallucinations to build botnets
Researchers have identified a novel attack vector called HalluSquatting that exploits the tendency of Large Language Models (LLMs) to hallucinate non-existent repository and package names. By predicting which identifiers an AI coding assistant is likely to invent when asked to clone trending software, attackers can pre-register those names on public registries like GitHub or PyPI. These malicious repositories are seeded with instructions that trigger the assistant’s built-in terminal to execute payloads, such as reverse shells or ransomware. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
