AI Tools Vulnerable to HalluSquatting: Massive Botnet Risk
The hallucination that becomes a supply chain
The newest generation of AI coding agents — Cursor, GitHub Copilot, Gemini CLI, Windsurf, and others — clone a repo, install a dependency, or wire up an API in response to a one-line prompt. It's a real productivity enable, and it's why so many teams have rebuilt their daily loop around these tools. A paper from Tel Aviv University and partner institutions surfaced a category of attack that lives in the gap between "the model wanted to help" and "the resource it reached for actually existed." They named it HalluSquatting (source), and every coding agent that auto-retrieves code is in scope.
This is an excerpt. Read the full post at otf-kit.dev/blog/ai-tools-botnets-risk — full-stack kits your AI coding agent can actually ship to production. Browse the kits →
Ship the product, not the setup.
- 11 production screens — auth, billing, team, analytics, settings
- Real database, payments, and login — all wired on day 1
- AI configs pre-tuned so your agent extends instead of regenerates