AI Coding Assistants Hallucinate Package Names, Opening Door to 'Slopsquatting' Attacks
AI coding assistants sometimes recommend non-existent package names with convincing, ecosystem-appropriate names — a phenomenon researchers call hallucination. Attackers are exploiting this by registering those commonly hallucinated names on PyPI and npm and publishing malicious packages under them, a technique dubbed 'slopsquatting'. In a recent incident reported by The Register, a human reviewer caught the threat by noticing a suggested package had almost no download history, preventing a potential compromise. Standard dependency-scanning tools like Snyk or Dependabot cannot detect these packages because newly registered, zero-download packages carry no known CVEs. No automated checkpoint currently exists between an AI's package suggestion and a developer running the install command, leaving manual review as the only reliable safeguard — one that is easily skipped under deadline pressure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in