Researchers found that attackers can exploit popular AI tools to help assemble large botnets. The technique, described as HalluSquatting, abuses models' tendency to invent package names or dependencies.

The risk is practical because developers increasingly copy AI-suggested commands, package names, and code into real environments. If attackers register plausible hallucinated packages, AI-assisted workflows can become a software supply-chain vector.

The finding is another reminder that AI coding tools need verification layers, especially around dependency installation and generated setup instructions.