Hospitals are hurling forward with agentic AI adoption, inking licensing deals with Anthropic, OpenAI and OpenEvidence, and encouraging the agentic push at ambient providers like Abridge. Each new AI integration, however, adds layers of supply-chain interdependence, and exposes enterprises to new, often unidentified risks. Groundbreaking research from a team Tel Aviv University, Technion, and Intuit exposed an agentic AI malware angle, termed adversarial hallucination squatting (or hallusquatting for short), previously unknown to cybersecurity and health professionals.
Hallusquatting exploits AI hallucination
While prior research established that threat actors can push adversarial prompts directly to LLM agents – like compelling ChatGPT to generate sexually explicit content or manipulating Claude into providing recipes for explosives – hallusquatting is the first threat channel known to indirectly poison LLMs.
Hallusquatting exploits the tendency of LLMs to hallucinate resources when assigned with research tasks. Through hallusquatting, attackers preregister a fake repository of trending hallucinated resources, and package them with adversarial prompts which can: prompt malicious code execution; encourage unsafe tool use; broaden supply chain exposure; and compromise dependencies. Because the attack angle is indirect, hallusquatting is executable at scale – the research team claims that research-tested AI models generated hallucinated resources at a rate of up to 85%, making the promptware broadly transferable.
Real clinical risk
Many AI systems deployed in clinical settings – like OpenEvidence, Claude Science, ChatGPT for Healthcare, and Abridge – use LLM interfaces to recover evidence and make clinical recommendations.
Though prompt engineers have sounded the alarm at the risk of jailbreaking these models, direct prompt injection sounds relatively infeasible in clinical settings as only doctors interface with enterprise AI. That hallusquatters trap research-based models in botnets surfaces a new, previously unaccounted risk dimension. Researchers already demonstrated successful success attacks in 65% of qualified test cases, including infection of Google Gemini.
Similarly, the risk is not one-off. In AI-enabled workflows, AI is empowered to infer dependencies, fetch information and install packages before human intervention – without tracking hallucination and drift, any workflow can get caught in a botnet. The reminder is that each new level of AI integration, no matter how promising, adds new layers of dependencies and nascent risk. Continuous monitoring for accuracy, safety and security has thus become a governance imperative.
References
[1] https://arxiv.org/pdf/2607.07433
[2] https://www.gensee.ai/blogs/ai-first-trust-decision-hallusquatting-supply-chain.html

.png)
.png)
