[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhOvi3gxSsSG4tbMVJauYPK28ZrzS65KL3Yx8NgGH7ck":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"ac02c208-67f1-40c8-a753-157baa63d66f","ai-hallucinated-package-names-create-exploitable-supply-chain-attack-vector","6dfd69e8-ab4f-46a7-b821-1999b98fc994","AI Hallucinated Package Names Create Exploitable Supply Chain Attack Vector","AI coding assistants frequently hallucinate plausible-sounding but non-existent package names, repository paths, and domain names — and attackers can predict and pre-register these fake identifiers to inject malicious code. Because developers often trust AI-generated recommendations without independent verification, a single hallucinated dependency can silently compromise an entire development pipeline. This 'late-binding' attack requires no traditional exploit; the vulnerability is the unconditional trust placed in AI output. As AI-assisted development becomes ubiquitous, the attack surface for supply chain poisoning expands dramatically, affecting any organization that integrates AI coding agents into their workflows.","**Immediate actions:**\n- Audit all AI-generated dependency names, package references, and domain suggestions against authoritative registries before using them in any codebase.\n- Enable software composition analysis (SCA) tools in CI\u002FCD pipelines to automatically flag unrecognized or suspicious package identifiers.\n\n**Long-term improvements:**\n- Establish a mandatory human review gate for any new dependency introduced by an AI coding agent before it is merged into production branches.\n- Maintain an internal, approved package allowlist and configure package managers to block installations from sources outside that allowlist.\n- Train developers on AI-specific supply chain risks, including slopsquatting and hallucination-based attacks, as part of regular security awareness programs.\n\n**Detection measures:**\n- Monitor dependency manifests and lock files in version control for unexpected additions or changes introduced by automated AI tooling.\n- Implement real-time alerts for any build process that attempts to pull packages from newly registered or low-reputation repositories.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-218: Secure Software Development Framework (SSDF) — PW.4 (Reuse Existing, Well-Secured Software)","NIST CSF 2.0: GV.SC-06 (Supply Chain Risk Management)","OWASP Top 10: A06:2021 – Vulnerable and Outdated Components","SLSA Supply Chain Levels for Software Artifacts — Level 2+ provenance requirements","ISO\u002FIEC 27036-3: Information security for supplier relationships — ICT supply chain","published","2026-07-24T16:22:15.927731+00:00","2026-07-24T16:22:15.855+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fslopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack\u002F","slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack-29cf88","Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]