Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
2026-07-01T08:51:39Z•4cdbc28ee327adaa4b05aeee7a435239fa07713046510a950f5be6ef0eb72834
CL-STA-1062CVE-2026-0257TinyRCTai-agent-marketplaceai-securitybucket-hijackingcloud-logging-manipulationcloud-securitycredential-theftdetection-and-responsedomain-hallucinationespionagefluttershellglobal-namespacelarge-scale-credential-attacksmacosnpmopenclawpan-osphantom-squattingremote-code-executionsupply-chainvertex-ai
What happened
Unit 42 published a batch of research and threat briefs highlighting an expanding set of high‑impact supply‑chain and cloud risks. Key themes: AI supply‑chain abuse (phantom squatting / LLM‑hallucinated domains, malicious skills in marketplaces like ClawHub, and integrity risks for agent skills), cloud namespace and bucket hijacking across CSPs (including a Vertex AI Python SDK bucket‑squatting issue leading to cross‑tenant RCE), large‑scale credential campaigns targeting security vendor devices, active exploitation of PAN‑OS (CVE‑2026‑0257), npm ecosystem supply‑chain evolution (wormable/mult
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 4cdbc28ee327adaa4b05aeee7a435239fa07713046510a950f5be6ef0eb72834
- Enrichment time
- 2026-07-01T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.