Hackers can use 9 of the most popular AI tools to assemble massive botnets
Security researchers have demonstrated that attackers can exploit the autocomplete features of nine major AI coding assistants to generate malicious software packages. By creating fake repository names that mimic popular libraries, hackers leverage the models' tendency to hallucinate non-existent dependencies, which unsuspecting developers then integrate into their projects. This technique, known as HalluSquatting, automates the creation of botnets by tricking AI tools into recommending compromised code. The finding highlights a growing vulnerability in software supply chains where AI-assisted development tools prioritize plausible suggestions over verifiable accuracy.
Covered by 2 sources
- AArs Technica↗Dan GoodinJul 8
- HHacker News↗joozioJul 8