AI coding agents can hallucinate predictable repository, package, domain, and skill names, and attackers can register those names first to trick agents into fetching malicious content. The article shows how Slopsquatting, Phantom Squatting, and HalluSquatting exploit the same trust flaw across tools like Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw. #Slopsquatting #PhantomSquatting #HalluSquatting #Cursor #Windsurf #GitHubCopilot #Cline #GeminiCLI #OpenClaw
Keypoints
- AI agents can treat hallucinated names as verified commands.
- Attackers can pre-register predictable fake resources before agents fetch them.
- Slopsquatting, Phantom Squatting, and HalluSquatting share the same trust flaw.
- The risk extends into transitive dependencies and automated build pipelines.
- Pre-fetch verification and curated repositories are stronger defenses than scanning alone.