← Back to Model Beat
Products·Jul 8·all news from July 8, 2026

Hackers can use 9 of the most popular AI tools to assemble massive botnets

Security researchers have demonstrated that attackers can exploit the autocomplete features of nine major AI coding assistants to generate malicious software packages. By creating fake repository names that mimic popular libraries, hackers leverage the models' tendency to hallucinate non-existent dependencies, which unsuspecting developers then integrate into their projects. This technique, known as HalluSquatting, automates the creation of botnets by tricking AI tools into recommending compromised code. The finding highlights a growing vulnerability in software supply chains where AI-assisted development tools prioritize plausible suggestions over verifiable accuracy.

Covered by 2 sources

Related stories

ProductsApple Sues OpenAI for Trade Secret Theft in Blockbuster CaseJul 10 · 29 sourcesProductsAI Poses Biggest Security Challenge of Decade, UK’s Cooper WarnsJul 5 · 30 sourcesProductsMeta Debuts New AI Image-Generation Model Inside Chatbot, InstagramJul 7 · 21 sourcesProductsMeta's Muse Spark 1.1 API pricing squeezes OpenAI and Anthropic as the AI price war heats upJul 9 · 5 sources