New LLM Attack Can Trick AI Coding Assistants Into Running Malware
As generative AI becomes more widespread, AI coding assistants have emerged as important productivity tools for engineers, but they have also introduced new cybersecurity vulnerabilities. Traditional prompt-injection attacks typically require direct interaction between an attacker and a victim. A newly discovered vulnerability, however, exploits hallucinations generated by LLMs themselves to plant malware across the software supply chain at scale without direct contact, exposing development environments to an unprecedented risk of passive infection.
Researchers from Tel Aviv University, the Technion – Israel Institute of Technology and Intuit disclosed the new attack, dubbed HalluSquatting, in July 2026. Their research found AI hallucination rates of 85% when cloning repositories and as high as 100% when installing skills. Attackers can exploit this behavior by registering fictitious resources in advance, causing GitHub Copilot or Cursor to trigger malicious commands during automated installation.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.