HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First

Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A softly lit developer workspace at night with a laptop open showing a blurred terminal window and lines
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers have named a new attack HalluSquatting, where criminals register software package names that AI coding assistants routinely invent out of thin air.
  • AI coding tools regularly "hallucinate", meaning they confidently suggest software libraries that do not actually exist.
  • Attackers who claim these fake names first can publish malicious software under them, so the next developer who trusts the AI installs malware.
  • The technique builds on typosquatting, but the bait is invented by the AI itself, not by a human mistype.
  • Defences include locking installs to known-good package lists and training developers to verify anything an AI recommends before running it.

AI coding assistants have a well-known bad habit. Ask one where to grab a popular software tool, and it'll sometimes reply with a confident, real-sounding name for a project that simply doesn't exist.

New research, first reported by The Hacker News, turns that quirk into a weapon. The authors call it HalluSquatting: work out which fake names an AI reliably invents, register those names on the public software libraries developers download from, and wait.

When the next developer asks a similar question, the AI hands over the same made-up name. They type the install command, and the trap springs.

What is actually being attacked here?

The target is the software supply chain: the pipes developers use to pull in ready-made building blocks for their own apps. Sites like npm (for JavaScript) and PyPI (for Python) host millions of these free building blocks, called packages. Anyone can publish one.

Normally a developer types something like pip install requests and gets a trusted, popular tool. HalluSquatting abuses that trust. An AI assistant, asked how to solve a coding problem, might invent a package name that sounds plausible but was never real. If an attacker has already registered that exact name and stuffed it with malicious code, the developer's computer runs that code the moment they install it.

That can mean stolen credentials, a back door onto the developer's machine, or malware quietly sliding into whatever product the developer is building. In the worst case, poisoned code ships to the developer's own customers. We covered a related scenario on 3 July 2026, when researchers hijacked AI coding assistants using a fake error message and security tools raised no alarm.

How is this different from typosquatting?

Typosquatting is the older cousin. Attackers register names that look almost identical to popular tools, hoping a developer fat-fingers the spelling. reqeusts instead of requests, that sort of thing.

HalluSquatting flips the source of the mistake. The developer types perfectly; the AI is making things up. Because large language models tend to repeat their favourite hallucinations, the same fake name can surface again and again across thousands of conversations. That predictability is what makes the attack economical: a patient attacker seeds dozens of fake packages and waits for AI-assisted developers to walk into them.

What should developers and companies do?

Treat anything an AI suggests as a hint, not a fact. Before installing a package the assistant mentions, confirm it exists on the official registry, check how long it's been published, and glance at its download count. Brand-new packages with almost no downloads deserve suspicion.

Larger teams can go further. Lock builds to an approved list of packages. Use private mirrors of npm and PyPI so nothing arrives from the open internet without review. Turn on dependency scanning, which flags known-bad libraries automatically.

One thing worth naming clearly: multi-factor authentication (a second login step, usually a phone code) wouldn't have helped here. Nobody's account was broken into. This attack targets trust in the AI's output, not passwords. Training developers to slow down and verify is the honest fix.

Attackers are already banking on the AI not stopping its hallucination habit any time soon. They're right to.

© 2026 Threat Vectr