
Hackers weaponize AI code hallucinations to deliver malware via fake packages
Security researchers warn that AI coding assistants can hallucinate non-existent package names, which attackers can register as real repositories and hide malware inside. When these tools reference the fake packages, they clone them onto users’ machines, enabling automated, stealthy malware deployment. The vulnerability affects many assistants (Cursor, Copilot, Gemini, OpenClaw, etc.) with attack success rates reported between 85% and 100% depending on the task. Researchers from Tel Aviv University and Intuit notified AI companies, but the core issue remains: AI assistants can be confident liars, creating a broad risk for developers relying on AI-generated code.