Hackers can use 9 of the most popular AI tools to assemble massive botnets 23%

By Dan Goodin18%

7/8/2026, 7:00:51 AM

BS Summary: This article contains 31 faulty reasoning types, including Negativity Bias, Hasty Generalization, and Overconfidence Bias, with Ambiguity (Equivocation) as the most egregious example at 36.8% saturation with 434 hits. Analysis detected 2,459 faulty-reasoning hits from 1,180 analyzed words, generating a BS Score of 36.3% and a BS Rank of 23% (16,914 of 21,887 articles). This article is better (less manipulative) than 77.30% of the article peer group.

In the brief history of AI security, the prompt injection has quickly become the top threat. 
Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. 
This makes it trivial to surreptitiously inject malicious commands that the LLM readily follows. 
With no way to enforce this crucial boundary between trusted and untrusted sources, AI engine developers are left to erect elaborate guardrails designed to mitigate the damage rather than solve the root cause. 
To date, most prompt injections have fallen into a class known as push, in which each potential victim is targeted. 
For example, the adversary injects malicious instructions into an individual email or calendar invitation. 
Because the injection must then be sent (or pushed) to each specific target, the scale of the attack is limited, hampering mass exploits that hit the Internet at large. 
Meanwhile, pull-based attacks, in which an LLM actively seeks out the adversarial prompts planted on websites, remain limited. 
With no way to lure large numbers of LLMs to a malicious site, these sorts of attacks don’t scale either. 
Enter HalluSquatting 
Now, researchers have devised a pull-based attack that changes all that. 
A new attack the researchers have named HalluSquatting has the potential to assemble massive botnets, perform large-scale DDoSes, and infect devices at scale, a first for prompt-injection attacks. 
The attack works against AI coding assistants and agents, including Cursor, Cursor CLI, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw, and NanoClaw, which are all susceptible. 
In the normal course of performing day-to-day activities, these assistants and agents routinely pull code and other resources from repositories and registries. 
The HalluSquatting threat model. 
Credit: Spira et al. 
Short for adversarial hallucination squatting, HalluSquatting is built on an LLM’s inherent tendency to hallucinate the resource identifiers hosted in repositories and registries. 
It works against coding agents and assistants, which commonly access high-privilege command lines to run code from third-party resources. 
By predicting the identifiers LLMs are most likely to hallucinate and then registering and seeding them with instructions to install reverse shells or other malicious wares, the attack can indiscriminately infect massive numbers of devices without having to target each one. 
“The scalable property of the attack enables the attacker to compromise a large number of users with minimal effort by targeting popular resources, thereby maximizing the likelihood that the squatted resource will be retrieved,” the researchers wrote in a paper published Wednesday. 
“By exploiting integrated shells and terminals of agentic applications to run scripts and code, attackers can effectively ‘infect’ many independent agentic applications by embedding instructions to install reverse shells in the resources the attackers register. 
Gaining access to distributed computational resources under attacker control opens the door to several high impact outcomes allowing attackers to achieve various goals. 
For example, having the ability to compromise LLM applications with terminals allows the attacker to scale the number of ransomware attacks on different networks to maximize financial gain. 
Alternatively, attackers can aggregate compromised machines into a botnet and use it for tasks that rely on substantial computing power, including (1) large-scale cryptocurrency mining (e.g., Smominru, WannaMine) or (2) performing distributed denial of service (DDoS) attacks against victims (e.g., Mirai).” 
HalluSquatting is already receiving interest from fellow AI security researchers not involved in the study. 
“This is very cool research, and the threat is very real,” Michael Bargury, CTO of security firm Zenity, wrote in an email. 
“Like typosquatting, it’s a problem that’s not going away. 
At the end of the day, it’s about the level of agency we allow our agents. 
They *are* going to get fooled one way or the other. 
That should be our assumption, and we should be resilient to that.” 
Independent researcher Johann Rehberger wrote: 
What’s interesting is that it shows that LLM resource resolution can become an attack path and an attacker can first probe models to find high-probability hallucinated candidates (like repo names, skill identifiers,etc) to squat and wait for agents to resolve and use them. 
But the main point is that they found a cool technique to find resource names that are more likely by models to be used/confused with. 
And that could mean many agents falling for such attacks in the wild. 
AI tool makers frequently exaggerate the convenience and efficiency of their platforms. 
Marketers claim the platforms lighten workflows by automating and streamlining tedious tasks. 
They are much more reticent about the inherent flaws that can torpedo an entire project. 
Attacks like HalluSquatting provide a potent reminder that some of the efficiencies are exaggerated since, at the end of the day, users must double-check details such as the location for each resource incorporated into a project. 
It also provides a cautionary lesson on the unintended and potentially dire outcomes that can result when people rely too heavily on AI assistants. 
LLMs don’t know how to say “I don’t know.” 
The starting point for HalluSquatting is the inability of LLMs to accurately identify the location of a resource specified by the user. 
When a developer, for instance, instructs a coding agent to clone a popular new repository, the LLM hallucinates its correct location up to 85 percent of the time. 
When cloning a trending “skill,” a form of instruction, script, or resource that gives agents specialized capabilities and domain expertise, hallucinations can occur 100 percent of the time. 
HalluSquatting focuses on trending resources because they aren’t included in the LLM training. 
They also receive large numbers of downloads over a short period of time. 
Table depicting the most frequently hallucinated owner/repo candidate per (target repository, foundational LLM) combination over 100 queries. 
Owner shading: yellow = real GitHub owner, blue = registrable squat (owner does not exist on GitHub), red = misdirection (real but unintended owner), purple = placeholder string that cannot be registered as a GitHub username. 
A  marks self-referential hallucinations (owner == repository name). 
Credit: Spira et al. 
The researchers say the inability of LLMs to provide the correct location is an inherent flaw that arises from training biases or from misinterpretations of instructions within the current context. 
That means when a user prompts the coding assistant to clone a repository or skill—in the form of, say, “clone repo name” or “install skill name”—the bot frequently navigates to the wrong location to retrieve it. 
Not only are these hallucinations inevitable, but they also occur at the foundational level of all six of the major LLMs, including Gemini-2.5-flash, Gemini-2.5-pro, GPT-5.1, GPT-5.2, Sonnet-4.5, and Opus-4.5. 
Additionally, the most commonly provided incorrect locations that these LLMs hallucinate are easy to predict in advance. 
All six LLMs follow common patterns when resolving the repository or skill name in a prompt with its official name in a repository or skill repository. 
LLMs follow various hallucination patterns. 
The one HalluSquatting exploits is described as being self-referential. 
All six models produce repo-name/repo-name slugs that treat a repository name as the owner. 
Exploiting the pattern requires no model probing. 
Article reasoning-pattern comparisonThis article: 2.3%Dan Goodin: 0.8%Ars Technica: 2.8%Confirmation Bias2.3%This article: 0.0%Dan Goodin: 0.9%Ars Technica: 1.2%Anchoring Bias0.0%This article: 10.3%Dan Goodin: 3.2%Ars Technica: 2.4%Availability Heuristic10.3%This article: 6.2%Dan Goodin: 1.2%Ars Technica: 1.0%Representativeness Heuristic6.2%This article: 0.0%Dan Goodin: 0.8%Ars Technica: 0.6%Hindsight Bias0.0%This article: 13.4%Dan Goodin: 3.0%Ars Technica: 2.1%Overconfidence Bias13.4%This article: 1.4%Dan Goodin: 2.5%Ars Technica: 3.4%Framing Effect1.4%This article: 0.0%Dan Goodin: 0.3%Ars Technica: 0.5%Loss Aversion0.0%This article: 1.8%Dan Goodin: 0.4%Ars Technica: 0.5%Status Quo Bias1.8%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Sunk Cost Effect0.0%This article: 4.7%Dan Goodin: 1.0%Ars Technica: 4.2%Optimism Bias4.7%This article: 9.9%Dan Goodin: 2.9%Ars Technica: 1.7%Pessimism Bias9.9%This article: 29.2%Dan Goodin: 6.6%Ars Technica: 6.2%Negativity Bias29.2%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 1.2%Self-Serving Bias0.0%This article: 4.5%Dan Goodin: 0.8%Ars Technica: 0.6%Fundamental Attribution Error4.5%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Actor-Observer Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.6%In-Group Bias0.0%This article: 2.3%Dan Goodin: 0.9%Ars Technica: 0.2%Out-Group Homogeneity Bias2.3%This article: 2.1%Dan Goodin: 0.8%Ars Technica: 2.0%Halo Effect2.1%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Horn Effect0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.0%Dunning-Kruger Effect0.0%This article: 3.2%Dan Goodin: 1.0%Ars Technica: 1.0%Recency Bias3.2%This article: 0.0%Dan Goodin: 0.2%Ars Technica: 0.3%Primacy Effect0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Blind-Spot Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.5%Ad Hominem0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Straw Man0.0%This article: 10.3%Dan Goodin: 3.2%Ars Technica: 4.1%Appeal to Authority10.3%This article: 4.5%Dan Goodin: 1.3%Ars Technica: 1.1%False Dilemma4.5%This article: 2.0%Dan Goodin: 0.2%Ars Technica: 0.7%Slippery Slope2.0%This article: 0.0%Dan Goodin: 0.2%Ars Technica: 0.1%Circular Reasoning0.0%This article: 14.4%Dan Goodin: 7.0%Ars Technica: 3.8%Hasty Generalization14.4%This article: 3.5%Dan Goodin: 0.4%Ars Technica: 0.2%Red Herring3.5%This article: 1.3%Dan Goodin: 0.8%Ars Technica: 0.6%Bandwagon1.3%This article: 7.5%Dan Goodin: 1.0%Ars Technica: 2.7%Appeal to Emotion7.5%This article: 0.9%Dan Goodin: 0.1%Ars Technica: 0.6%Begging the Question0.9%This article: 12.5%Dan Goodin: 2.2%Ars Technica: 2.3%Post Hoc (False Cause)12.5%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Tu Quoque0.0%This article: 1.0%Dan Goodin: 0.1%Ars Technica: 0.5%Burden of Proof1.0%This article: 0.8%Dan Goodin: 0.8%Ars Technica: 0.2%Appeal to Nature0.8%This article: 0.0%Dan Goodin: 0.9%Ars Technica: 0.2%Composition/Division0.0%This article: 2.1%Dan Goodin: 0.5%Ars Technica: 1.5%Anecdotal2.1%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%No True Scotsman0.0%This article: 36.8%Dan Goodin: 6.6%Ars Technica: 1.7%Ambiguity (Equivocation)36.8%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.0%Gambler’s Fallacy0.0%This article: 1.4%Dan Goodin: 0.3%Ars Technica: 0.1%Middle Ground1.4%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Personal Incredulity0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Special Pleading0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Genetic Fallacy0.0%This article: 3.0%Dan Goodin: 1.8%Ars Technica: 1.5%Unattributed Quote3.0%This article: 8.4%Dan Goodin: 2.9%Ars Technica: 1.0%Quote-first Misdirection8.4%This article: 4.5%Dan Goodin: 4.0%Ars Technica: 4.5%Biased Writer Voice4.5%This article: 2.4%Dan Goodin: 2.2%Ars Technica: 1.0%Indoctrination2.4%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.7%Politically Left Leaning Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Politically Right Leaning Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 1.3%Attempt to Sell a Product or S…0.0%

1180 words analyzed.

Speakers

2speakers13%attributed speech1,024writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 14 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 33 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 28 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 41 words • 0.0% coverageWriter's voice • 42 words • 100.0% coverageWriter's voice • 35 words • 100.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 41 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageMichael Bargury • 22 words • 100.0% coverageMichael Bargury • 9 words • 0.0% coverageMichael Bargury • 16 words • 100.0% coverageMichael Bargury • 11 words • 0.0% coverageMichael Bargury • 12 words • 100.0% coverageJohann Rehberger • 5 words • 0.0% coverageJohann Rehberger • 43 words • 0.0% coverageJohann Rehberger • 25 words • 100.0% coverageJohann Rehberger • 13 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverage
Selected voice

Michael Bargury

100%flagged-word coverage
70 attributed words45% of attributed speech83% writer coverage
0%20.0%40.0%Indoctrination+40.0 ptsWriter: 0.0%Michael Bargury: 40.0%40.0%Quote-first Misdirection+23.9 ptsWriter: 7.5%Michael Bargury: 31.4%31.4%Unattributed Quote-3.4 ptsWriter: 3.4%Michael Bargury: 0.0%0.0%Biased Writer Voice-2.7 ptsWriter: 2.7%Michael Bargury: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.