So much so, in fact, that cybersecurity researchers warn that criminals can easily weaponize delusional AI outputs to spread malware throughout the internet. According to SecurityWeek, the attack works by exploiting a persistent flaw in AI coding assistants. To run it, attackers can simply identify hallucinated package names that they know AI coding assistants will reference, register them as real repositories, and stuff malware inside. And because the compromise is a feature of the technology itself, a massive array of AI assistants are vulnerable, including Cursor, OpenClaw, Gemini, GitHub Copilot, and many more. More on AI: A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There