cd /news/ai-safety/if-you-ai-generate-code-hackers-just… · home topics ai-safety article
[ARTICLE · art-78862] src=futurism.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

If You AI-Generate Code, Hackers Just Found a Devious Method to Install Malware Directly on Your Computer

Cybersecurity researchers at Tel Aviv University and Intuit have identified a new attack called 'hallusquatting' that exploits AI coding assistants' tendency to hallucinate non-existent software package names, allowing attackers to register those names as real repositories containing malware. The attack affects tools including Cursor, Microsoft's Copilot, Gemini, and GitHub Copilot, with success rates of 85 to 100 percent depending on the task. Researchers notified AI companies but warn the underlying flaw remains unpatched.

read1 min views1 publishedJul 29, 2026
If You AI-Generate Code, Hackers Just Found a Devious Method to Install Malware Directly on Your Computer
Image: Futurism (auto-discovered)

Despite certain improvements in accuracy, large language models still hallucinate a lot. So much so, in fact, that cybersecurity researchers warn that criminals can easily weaponize delusional AI outputs to spread malware throughout the internet.

According to SecurityWeek, the attack works by exploiting a persistent flaw in AI coding assistants. Basically, when these tools recommend third-party software packages, there’s a strong possibility that they include names of ones that don’t actually exist.

Astonishingly, cybersecurity researchers at Tel Aviv University and Intuit found that this scenario can be exploited in common AI coding tools ranging from Cursor to Microsoft’s Copilot, at rates of anywhere form 85 to 100 percent, depending on the specifics of the engineering task.

The attack, called “adversarial hallucination squatting,” or “hallusquatting,” takes advantage of this fact. To run it, attackers can simply identify hallucinated package names that they know AI coding assistants will reference, register them as real repositories, and stuff malware inside. That malicious package then lies in wait for the near-guarantee than an AI assistant will access it and clone it into its owner’s machine.

Because the attack relies on an automated process, a victim likely won’t even know their AI assistant downloaded the malware until well after it begins executing code.

And because the compromise is a feature of the technology itself, a massive array of AI assistants are vulnerable, including Cursor, OpenClaw, Gemini, GitHub Copilot, and many more.

The researchers claim they notified AI companies about the exploit and held back some sensitive details that would help attackers improve their workflows, but the underlying problem remains: AI assistants are remarkably confident liars — and apparently easy marks for the next generation of cyber criminals**.**

── more in #ai-safety 4 stories · sorted by recency
── more on @tel aviv university 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/if-you-ai-generate-c…] indexed:0 read:1min 2026-07-29 ·