HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code. The technique abuses predictable hallucinated package or plugin names, turning a naming error into attacker code execution and a plausible path to botnet installation across many machines. In tests against Cursor, Windsurf, GitHub Copilot, Cline, and Gemini CLI, the same wrong name was often reused, showing the attack can be repeatable at scale. The finding raises risk for any assistant with fetch-and-run permissions and limited human review.
Related Happenings
Google CodeMender becomes a fully managed enterprise AI code security agent in Google Cloud
Security Tool/Service
H score12
First: 22.07.2026 13:30
Last: 22.07.2026 13:30
Sources 1
About this happening:
Google CodeMender has moved from research into a fully managed enterprise AI code security agent inside Google Cloud, expanding automated vulnerability discovery and r...
Google CodeMender becomes a fully managed enterprise AI code security agent in Google Cloud
Security Tool/ServiceAbout this happening: Google CodeMender has moved from research into a fully managed enterprise AI code security agent inside Google Cloud, expanding automated vulnerability discovery and r...
Reproduced cross-vendor sandbox escapes in AI coding agents
Technical Analysis
H score22
First: 21.07.2026 00:14
Last: 21.07.2026 00:14
Sources 1
About this happening:
Researchers reproduced sandbox-escape bypasses across Cursor, Codex, Gemini CLI, and Antigravity, showing that agentic coding tools can cross the sandbox bound...
Reproduced cross-vendor sandbox escapes in AI coding agents
Technical AnalysisAbout this happening: Researchers reproduced sandbox-escape bypasses across Cursor, Codex, Gemini CLI, and Antigravity, showing that agentic coding tools can cross the sandbox bound...
Agent data injection proof-of-concept attacks expose trusted-data flaws in AI agents
Technical Analysis
H score25
First: 16.07.2026 14:32
Last: 16.07.2026 14:32
Sources 1
About this happening:
Researchers disclosed agent data injection (ADI), a new attack class that can make shipping AI agents misclick, run attacker commands, and trust fake history across web and co...
Agent data injection proof-of-concept attacks expose trusted-data flaws in AI agents
Technical AnalysisAbout this happening: Researchers disclosed agent data injection (ADI), a new attack class that can make shipping AI agents misclick, run attacker commands, and trust fake history across web and co...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical Analysis
H score25
First: 11.07.2026 12:03
Last: 11.07.2026 12:03
Sources 1
About this happening:
Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical AnalysisAbout this happening: Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical Analysis
H score28
First: 10.07.2026 16:45
Last: 10.07.2026 16:45
Sources 1
About this happening:
Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical AnalysisAbout this happening: Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Timeline
-
08.07.2026 18:07 2 articles · 14d ago
Researchers disclose HalluSquatting code execution against AI coding assistants
Initial DisclosureResearchers from Tel Aviv University, Technion, and Intuit disclosed HalluSquatting, an indirect prompt-injection technique that targets AI coding assistants by pre-registering hallucinated package or repository names on GitHub or a plugin store, then feeding the assistant attacker-controlled content so its command-running tool executes attacker code. In testing, Cursor, Windsurf, GitHub Copilot, Cline, Google's Gemini CLI, and the OpenClaw family of assistants were driven to run attacker code, with the same wrong name recurring in up to 85% of repository requests and 100% of skill installs; the authors said the technique could help assemble a botnet and that they notified affected vendors, model makers, and marketplace operators before going public.
Show sources
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware — thehackernews.com — 08.07.2026 18:07
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware — thehackernews.com — 08.07.2026 18:07