Hackers weaponize AI code hallucinations to deliver malware via fake packages

Security researchers warn that AI coding assistants can hallucinate non-existent package names, which attackers can register as real repositories and hide malware inside. When these tools reference the fake packages, they clone them onto users’ machines, enabling automated, stealthy malware deployment. The vulnerability affects many assistants (Cursor, Copilot, Gemini, OpenClaw, etc.) with attack success rates reported between 85% and 100% depending on the task. Researchers from Tel Aviv University and Intuit notified AI companies, but the core issue remains: AI assistants can be confident liars, creating a broad risk for developers relying on AI-generated code.
- If You AI-Generate Code, Hackers Just Found a Devious Method to Install Malware Directly on Your Computer Futurism
- Coding assistants can be tricked by malicious symlinks IT Brew
- Malware is targeting AI tools in software development environments CyberScoop
- An AI agent can pass every safety check and still leak secrets Help Net Security
- Hackers are hiding malware behind AI agents that antivirus cannot see TechCentral
Reading Insights
1
6
1 min
vs 2 min read
73%
355 → 95 words
Want the full story? Read the original article
Read on Futurism