← Back to Feed

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

July 1, 2026 · Unit 42 · Severity: HIGH

Unit 42's analysis of phantom squatting reveals how attackers exploit LLM domain hallucinations to register domains that AI models falsely generate. These hallucinated domains become vectors for software supply chain attacks when developers use AI-generated code without verification. The technique represents a novel AI-driven supply chain risk.

Key Takeaways

  • Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector — Attackers can exploit LLM domain hallucinations through phantom squatting to target supply...
  • High-severity alert: organizations should assess their exposure and apply mitigations promptly.
  • AI and LLM usage introduces new attack surfaces, including hallucinated domains and prompt injection risks.
  • Supply chain compromises enable cascading attacks; third-party risk assessments are a critical security control.
  • Immediate investigation and remediation are recommended based on the severity of this threat.
☕ Buy a Coffee