The article describes slopsquatting, a supply-chain attack in which an attacker registers a package name that an AI coding assistant has hallucinated, hoping developers or agents will install the malicious package. Unlike typosquatting, which exploits misspelled names, the attack relies on plausible-sounding names generated by AI. The article says the term was coined in 2025 by Seth Larson of the Python Software Foundation and presents research figures on how often models invent package names. It cites rates as high as about 22% for some open-source models, 3.59% for GPT-4 Turbo, and roughly 4.6%–6.1% in a 2026 evaluation of newer frontier models.
The article emphasizes that hallucinations can be repeatable: in one cited test, 43% of invented names recurred across repeated runs of the same prompts, and another study found 127 package names independently produced by five frontier models. Conventional typosquatting defenses may miss these names because many are not close spellings of existing packages. The author recommends treating AI-proposed dependencies as untrusted, checking that packages exist and are legitimate, pinning versions and hashes, limiting installs to approved packages, and reviewing new dependencies in CI. Teams using autonomous coding agents are urged to gate installation behind verification or approval. The article also discloses the author’s connection to Xenition, a company working on install gates, while stressing that the safety principle is more important than any particular tool.
NewsBite reading:AI-hallucinated package names create a software supply-chain risk
The article highlights a supply-chain threat pattern in which attackers can target package names repeatedly suggested by AI systems, and frames AI-generated install commands as untrusted input requiring verification.
Unchanged: The article does not report a newly discovered CVE, a confirmed attack campaign, a specific victim, or a change to package managers. Standard dependency controls remain applicable, though the article argues they should account for AI-generated suggestions.
The article is cautionary: it presents slopsquatting as a measurable, repeatable risk while emphasizing that layered dependency controls can reduce exposure. It does not claim a specific successful attack or victim.
The article outlines a software supply-chain attack avenue that could result in malicious dependencies entering projects.
AI-generated code can include fabricated package names, adding verification work and risk to common development workflows.
The cited model hallucination rates indicate that package suggestions can be confidently wrong, even in newer systems.
Dependency scanning, CI review, lockfiles, and install gates offer practical mitigations, but existing string-similarity defenses may not detect these names.
The article credits him with coining the term slopsquatting in 2025.
The article identifies it as Seth Larson’s affiliation when describing the origin of the term.
The article cites a 3.59% package-name hallucination rate for this model in a referenced study.
The author discloses working on the company and says it is developing install gates, creating relevant context for the proposed mitigation.
Unchecked AI-generated package suggestions can expose projects to malicious dependencies.
“Treat any package name an LLM gives you as untrusted input”
Unrestricted dependency installation by people or agents can create supply-chain exposure.
“Gate its installs behind verification or approval”
A package installation can introduce third-party code directly into a development or production supply chain. Repeated hallucinations make some nonexistent names potentially predictable, while ordinary typo-detection tools may not recognize plausible but dissimilar names. The suggested controls shift trust decisions from the model to package verification, approved registries, and review gates. The article describes a documented risk and mitigations, not a confirmed incident or evidence that any particular package has been maliciously registered this way.
Developers may unknowingly install malicious dependencies when they trust generated install commands without checking package identity and provenance.
Organizations that permit AI-assisted development or autonomous agents to add dependencies face potential supply-chain exposure unless installation is controlled and reviewed.
Small teams may rely heavily on AI-generated code while having fewer formal dependency review controls.
The article discusses AI coding tools and open-source package ecosystems without limiting the risk or recommendations to a particular region.
May add approval steps or dependency allow-lists to prevent agents from installing unvetted packages.
May face demand for controls that detect suspicious package introductions beyond simple name-similarity checks.
May be pressed to surface package provenance or gate suggested installation commands more clearly.
The described technique could introduce malicious code through software dependencies, though no particular successful attack is documented.
The article focuses on dependency integrity, not data collection, processing, or governance.
A compromised dependency could damage trust in affected software or in AI-assisted development practices.
Implementing verification, allow-lists, and agent approval gates requires workflow changes; the article does not quantify their cost or effectiveness.
A malicious dependency could affect build and deployment pipelines, but the article reports no specific infrastructure compromise.
The article describes a software supply-chain threat without identifying a geopolitical actor or state-linked activity.
No regulatory action or legal requirement is discussed.
The central issue is the possibility that attackers register hallucinated package names and developers install them as dependencies.
The article does not discuss job displacement or changes to staffing.
Organizations may need controls around AI-generated dependency suggestions, but the article reports no legal claim or liability ruling.
The automated analysis found no sources named in the text.