Tel Aviv U, Technion, Intuit researchers publish HalluSquatting pull-based attack. LLM hallucinates package/repo URLs; attackers pre-register malicious payloads. 85-100% hallucination on trending resources.