Hackers weaponize AI code hallucinations to deliver malware via fake packages

1 min read
Source: Futurism
Hackers weaponize AI code hallucinations to deliver malware via fake packages
Photo: Futurism
TL;DR Summary

Security researchers warn that AI coding assistants can hallucinate non-existent package names, which attackers can register as real repositories and hide malware inside. When these tools reference the fake packages, they clone them onto users’ machines, enabling automated, stealthy malware deployment. The vulnerability affects many assistants (Cursor, Copilot, Gemini, OpenClaw, etc.) with attack success rates reported between 85% and 100% depending on the task. Researchers from Tel Aviv University and Intuit notified AI companies, but the core issue remains: AI assistants can be confident liars, creating a broad risk for developers relying on AI-generated code.

Share this article

Reading Insights

Total Reads

1

Unique Readers

6

Time Saved

1 min

vs 2 min read

Condensed

73%

35595 words

Want the full story? Read the original article

Read on Futurism