Slopsquatting: How AI Package Hallucinations Are Enabling Supply Chain Attacks

A new cyberattack technique called slopsquatting exploits AI coding assistants that confidently recommend non-existent software packages, which attackers then register to deliver malicious code. The term was coined by Seth Larson of the Python Software Foundation and brought to wider attention by Andrew Nesbitt of Ecosyste.ms in 2025. Unlike typosquatting, which relies on human typing errors, slopsquatting targets developers who trust and copy AI-generated package names without verification. A USENIX Security 2025 study found that nearly 20% of packages recommended by 16 large language models across 576,000 code samples did not actually exist. Critically, 43% of hallucinated package names reappeared consistently across repeated prompts, giving attackers a reliable list of high-value fake names to register in advance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in