There’s a very specific flavor of dumb in cybersecurity right now, and it belongs to your AI coding assistant. Researchers from Tel Aviv University, Technion, and Intuit just published an attack called “HalluSquatting,” and the mechanism is almost insultingly simple: your coding agent hallucinates a package or repo name that doesn’t exist, and an attacker who saw that coming has already registered it — stuffed with malware.
Here’s how it plays out. Ask Cursor, GitHub Copilot, Windsurf, Cline, Gemini CLI, or OpenClaw to clone a repo or install a “skill,” and these tools will sometimes confidently invent a name that sounds plausible but was never real — the same species of confabulation as an AI citing a court case that doesn’t exist. Normally that’s just an annoying wrong answer. But an attacker who’s been probing the same models can predict which fake names they’re likely to dream up, register those names for real on GitHub or npm ahead of time, and load them with a payload. When your assistant hallucinates the name and pulls it down through its own terminal access, it doesn’t just suggest bad code — it executes the attacker’s commands directly, no click required from you.
Traditional botnets spread through weak passwords and unpatched boxes. This one spreads through your coding assistant’s imagination.
The numbers are the part that should actually worry you: the researchers measured hallucination rates up to 85% in repo-cloning tasks and up to 100% in certain skill-installation scenarios. That’s not an edge case — that’s the median outcome for entire categories of prompts. And because the exploit rides in through the model’s own hallucination rather than a phishing link or malicious attachment, it slides past every defense built for how humans get owned, not how AI agents do.
The uncomfortable subtext is that this isn’t a bug you patch — it’s the tradeoff of giving an LLM a terminal and telling it to be fast and helpful. Every “agentic coding” pitch of the last two years has been “let it just do the thing,” and this is what “just do the thing” looks like when the thing it does is invent a URL and then trust it.
None of this means throw your Cursor subscription in the bin. It means the same discipline that used to apply to random npm installs off Stack Overflow now applies to whatever your AI just typed into a terminal on your behalf — check what actually got pulled down before you run it, and put something between the agent and blind execution that actually inspects the package instead of trusting the vibes.
The direct defense here isn't "trust the AI less" — it's putting an automated check between your coding agent and its terminal. Aikido Security's code-to-runtime platform (SAST, SCA, and supply-chain scanning) is built to catch exactly this: a newly-registered, suspicious package flagged before it executes, not after.
Good week to actually read what your AI just installed.
มีความโง่แบบเฉพาะทางที่กำลังเกิดขึ้นในวงการความปลอดภัยไซเบอร์ตอนนี้ และมันเป็นของ AI coding assistant ของคุณเอง นักวิจัยจาก Tel Aviv University, Technion และ Intuit เพิ่งเผยแพร่การโจมตีที่ชื่อว่า “HalluSquatting” และกลไกของมันง่ายจนแทบจะดูถูกสติปัญญา คือ AI ผู้ช่วยเขียนโค้ดของคุณ “หลอน” (hallucinate) ชื่อแพ็กเกจหรือรีโพที่ไม่มีอยู่จริงขึ้นมา แล้วแฮกเกอร์ที่คาดเดาไว้ล่วงหน้าก็จดทะเบียนชื่อนั้นไว้แล้ว พร้อมยัดมัลแวร์เข้าไปเรียบร้อย
กลไกเป็นแบบนี้ ลองสั่งให้ Cursor, GitHub Copilot, Windsurf, Cline, Gemini CLI หรือ OpenClaw โคลนรีโพหรือติดตั้ง “skill” ดู เครื่องมือเหล่านี้บางครั้งจะมั่นใจสุด ๆ ในการสร้างชื่อที่ฟังดูสมเหตุสมผลแต่ไม่เคยมีอยู่จริงขึ้นมา เป็นอาการเดียวกับที่ AI อ้างอิงคดีความในศาลที่ไม่มีอยู่จริง ปกติแล้วมันก็แค่คำตอบผิดที่น่ารำคาญ แต่แฮกเกอร์ที่คอยสังเกตโมเดลเดียวกันสามารถคาดเดาได้ว่าชื่อปลอมแบบไหนที่ AI มักจะ “ฝัน” ขึ้นมา แล้วไปจดทะเบียนชื่อเหล่านั้นจริง ๆ บน GitHub หรือ npm ไว้ล่วงหน้า พร้อมใส่เพย์โหลดอันตรายเข้าไป เมื่อผู้ช่วย AI ของคุณหลอนชื่อนั้นขึ้นมาแล้วดึงมันลงมาผ่านเทอร์มินัลของตัวเอง มันไม่ได้แค่แนะนำโค้ดแย่ ๆ เท่านั้น แต่มันรันคำสั่งของแฮกเกอร์โดยตรง ไม่ต้องมีการคลิกใด ๆ จากคุณเลย
บอตเน็ตแบบดั้งเดิมแพร่กระจายผ่านรหัสผ่านที่อ่อนแอและเครื่องที่ไม่ได้แพตช์ แต่ตัวนี้แพร่กระจายผ่านจินตนาการของผู้ช่วยเขียนโค้ด AI ของคุณเอง
ตัวเลขคือส่วนที่ควรทำให้คุณกังวลจริง ๆ นักวิจัยวัดอัตราการหลอนได้สูงถึง 85% ในงานโคลนรีโพ และสูงถึง 100% ในบางสถานการณ์การติดตั้ง skill นี่ไม่ใช่กรณีขอบ ๆ แต่เป็นผลลัพธ์ปกติของพรอมป์ทั้งหมวดหมู่ และเพราะการโจมตีนี้อาศัยอาการหลอนของโมเดลเอง ไม่ใช่ลิงก์ฟิชชิงหรือไฟล์แนบอันตราย มันจึงหลบเลี่ยงการป้องกันที่ถูกออกแบบมาสำหรับวิธีที่มนุษย์โดนหลอก ไม่ใช่วิธีที่ AI agent โดนหลอก
ประเด็นที่น่าอึดอัดคือ นี่ไม่ใช่บั๊กที่แพตช์ได้ แต่เป็นข้อแลกเปลี่ยนของการให้ LLM เข้าถึงเทอร์มินัลแล้วบอกให้มันช่วยเหลือแบบรวดเร็ว ทุกการขายไอเดีย “agentic coding” ในช่วงสองปีที่ผ่านมาคือ “ปล่อยให้มันทำเองเลย” และนี่แหละคือหน้าตาของ “ปล่อยให้มันทำเองเลย” เมื่อสิ่งที่มันทำคือการสร้าง URL ขึ้นมาเองแล้วก็เชื่อมัน
ทั้งหมดนี้ไม่ได้แปลว่าให้เลิกใช้ Cursor แต่แปลว่าวินัยแบบเดียวกับที่เคยใช้กับการติดตั้ง npm สุ่ม ๆ จาก Stack Overflow ตอนนี้ต้องใช้กับสิ่งที่ AI ของคุณเพิ่งพิมพ์ลงเทอร์มินัลแทนคุณด้วย ตรวจสอบว่าอะไรถูกดึงลงมาจริง ๆ ก่อนรัน และวางบางอย่างไว้ระหว่าง agent กับการรันแบบไม่ตรวจสอบ ที่ตรวจดูแพ็กเกจจริง ๆ แทนที่จะเชื่อความรู้สึก
ทางป้องกันโดยตรงตรงนี้ไม่ใช่ "เชื่อ AI น้อยลง" แต่คือการวางระบบตรวจสอบอัตโนมัติไว้ระหว่าง coding agent กับเทอร์มินัลของมัน แพลตฟอร์ม code-to-runtime ของ Aikido Security (SAST, SCA และการสแกน supply-chain) ถูกสร้างมาเพื่อจับสิ่งนี้โดยเฉพาะ คือแพ็กเกจที่เพิ่งจดทะเบียนใหม่และน่าสงสัยจะถูกตรวจพบก่อนที่มันจะถูกรัน ไม่ใช่หลังจากนั้น
สัปดาห์นี้เหมาะเป็นอย่างยิ่งที่จะลองอ่านจริง ๆ ว่า AI ของคุณเพิ่งติดตั้งอะไรลงไป
Sources:แหล่งข้อมูล: SecurityWeek, The Hacker News, Decrypt, SC Media