Security researchers from Tel Aviv University, Technion, and Intuit confirm that AI coding agents hallucinate predictable fake names for packages, domains, and repositories. The team tests multiple prompts across popular tools including Cursor, GitHub Copilot, Windsurf, and Gemini CLI. The results show that models hallucinate identical names up to 85%