// GeminiHIGH
HalluSquatting attack exploits LLM hallucinations in AI coding assistants including Gemini CLI. Attackers register fake repository names and packages that AI models are likely to hallucinate, tricking systems into retrieving and executing malicious code. Exploitation demonstrated across GitHub Copilot, Cursor, Windsurf, Gemini CLI, and other autonomous agents; hallucination rates reach 85-100% in certain scenarios. Researchers recommend stricter resource validation and reduced autonomous execution privileges.
// Get alerts for Gemini