DevHorrors Tool Scans Code Dependencies for AI-Hallucinated and Malicious Packages
A developer has launched DevHorrors, a free scanning tool designed to detect AI-hallucinated, typosquatted, and malicious packages in project dependency files. The tool addresses a growing threat called 'slopsquatting,' where AI coding assistants suggest non-existent package names that bad actors then register to distribute malware. Users can upload or paste a manifest file from npm, PyPI, Go, or RubyGems to receive an instant risk report with hallucination-confidence scores and suggested legitimate alternatives. The tool also includes a 'Roast Engine' that provides humorous yet actionable security critiques alongside remediation steps. A free API and CLI are available for CI/CD integration, with a paid tier offering team monitoring, Slack and Discord alerts, and GitHub pull request blocking.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in