Somewhere this week, a developer asked an AI coding assistant for a quick recommendation on a package to handle date formatting, and the assistant confidently pointed them to a GitHub repo and an install command for a library that does not exist. Not “doesn’t exist yet.” Doesn’t exist, full stop, except in the parts of a large language model’s training data where plausible-sounding names live next to real ones. That’s the joke of modern cybersecurity: we spent a decade teaching people not to click suspicious links, and now we’ve built tools that generate suspicious links on their own and hand them to us with total confidence.

Unit 42’s research on what it calls phantom squatting lays out exactly how this turns into a real attack, not a theoretical one. And it’s worth sitting with, because this is a supply chain problem that doesn’t require a single line of malicious code to get started. It just requires an LLM being wrong in a predictable way, and an attacker patient enough to notice the pattern.

So Your AI Assistant Just Invented A Website

Hallucination isn’t news. Anyone who’s used a chatbot for more than a week has caught it inventing a citation, a function that isn’t in the library, or a person who doesn’t exist. What Unit 42 documented is more specific and more dangerous: LLMs asked about software packages, APIs, or documentation will reliably hallucinate plausible-sounding domain names and repository URLs, often the same ones, repeatedly, because the model is pattern-matching on naming conventions rather than checking a directory.

That repeatability is the entire attack. If a model hallucinates fast-json-utils.dev once, it’s a fluke. If it hallucinates the same domain across thousands of queries because that’s the statistically “obvious” name for a package like that, an attacker can register it, stand up a convincing-looking package or site, and wait. No phishing email required. No compromised maintainer account. Just a name-shaped hole that the model keeps pointing people toward, and a squatter who got there first.

Abstract illustration representing AI-generated code and hallucinated web domains
AI coding assistants can hallucinate the same fake domain repeatedly, giving attackers a predictable target to squat on.

Why This Beats Old-Fashioned Typosquatting

Typosquatting has a defense that’s aged reasonably well: humans learn to double-check a URL before they type in a password. Slopsquatting, or phantom squatting, skips that step entirely because the recommendation isn’t coming from an ad, a text message, or a spoofed email. It’s coming from a tool the developer already trusts, embedded in their workflow, delivered as a matter-of-fact suggestion. There’s no red flag to notice because there’s no obvious deception, just an AI being wrong in a way that happens to align perfectly with what a squatter needs.

Scale that against real threat detection budgets and you get a problem worth taking seriously. Dark Reading reported this week on a China-linked group that quietly compromised at least ten organizations across Southeast Asia’s critical infrastructure, deploying a new backdoor along the way. Nobody’s claiming that campaign used hallucinated domains specifically. But it’s the same underlying story: professionalized, patient actors who understand that the easiest way in is rarely the front door. It’s whatever unglamorous gap nobody’s watching yet. Right now, that gap is a chatbot that can’t tell you “no” when you ask it something it doesn’t actually know.

What To Actually Do About It This Week

The fix isn’t banning AI coding tools, that ship sailed and isn’t coming back. The fix is treating every AI-suggested dependency, domain, or download the same way you’d treat an unsolicited link in an email: verify before you trust it. A few concrete moves that don’t require new budget or new vendors:

  • Pin dependencies to known-good versions from an internal or verified registry mirror, not whatever URL an assistant spits out mid-session.
  • Require a human to manually confirm any new package or domain suggested by an AI tool before it touches a build pipeline, no exceptions for “it looked fine.”
  • Bake domain and package-name verification into code review, treating it as part of security hardening rather than an afterthought.
  • Add threat-protection rules that flag first-seen domains or packages appearing in commit history or CI logs, since a brand-new name showing up out of nowhere is itself a signal.
  • Keep a defense in depth posture at the network layer too. A firewall or egress filter that blocks outbound connections to newly registered domains buys time even when a developer’s judgment doesn’t.

None of this replaces good incident response planning. If a hallucinated package does get pulled into a build, you want to know fast, which means logging what actually got installed and from where, not trusting that your dependency file tells the whole story. This is threat detection in its most basic form: knowing what’s supposed to be there so you notice what isn’t.

Meanwhile, Everyone’s Planning For Quantum Computers

Microsoft also used this week to talk up its accelerated quantum-safe timeline, encouraging organizations to start migrating cryptography now ahead of a threat that, by most credible estimates, is still years away from being operationally real. That’s not bad advice. Cryptographic migrations take forever and starting early is smart. But there’s something almost funny about the industry’s collective attention span here: we’re mobilizing serious resources against a threat that doesn’t exist yet, while a threat that very much does exist, AI tools inventing malicious infrastructure in real time, barely registers as a headline.

This isn’t an argument against quantum-safe planning. It’s an argument for triage. Cybersecurity budgets are finite and attention is more finite still. If your team has bandwidth to think about post-quantum cryptography, it has bandwidth to add one verification step to the AI-assisted parts of your development pipeline. The quantum apocalypse can wait for its turn in the queue. The chatbot that’s currently recommending fake websites to your engineers cannot.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.