[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPkPGxadfWV3Umv8CLlAqbXmQPMqgjnRvxj0i-uaU7uY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"d8ba751d-52e2-4fef-9a03-2c92ce24e641","ai-hallucinated-package-names-create-ready-made-supply-chain-attack-surface","42212641-b1d7-4c88-9058-819bad4aa216","AI Hallucinated Package Names Create Ready-Made Supply Chain Attack Surface","Large language models consistently hallucinate nonexistent package names at rates of roughly 5–6%, and researchers have identified 53 of these names as still-registrable on PyPI and npm — meaning attackers can simply claim these names and wait for AI tools to direct developers straight to their malicious code. This 'slopsquatting' attack requires no exploitation of existing software; the vulnerability is baked into the AI's outputs themselves. Unlike traditional typosquatting, a single malicious registration can affect developers using multiple AI providers simultaneously because the same hallucinated names recur across models. The risk is amplified by the growing norm of copy-pasting AI-generated code without independent verification, making developer security awareness a critical last line of defense.","**Immediate actions:**\n- Audit any AI-generated dependency lists against official package registries before installing or committing them to code.\n- Cross-reference all AI-suggested packages using tools like Socket, Snyk, or pip-audit to confirm legitimacy and check for malicious indicators.\n\n**Developer workflow improvements:**\n- Enforce a policy requiring human verification of every package name suggested by an AI coding assistant before inclusion in a project.\n- Integrate Software Composition Analysis (SCA) tools into CI\u002FCD pipelines to automatically flag unrecognized or newly registered packages.\n- Pin dependencies to specific, verified versions and use lock files (e.g., `requirements.txt`, `package-lock.json`) to prevent silent substitution.\n\n**Detection & monitoring measures:**\n- Monitor internal dependency usage logs for any package installations that originate from AI-tool recommendations and lack prior usage history.\n- Subscribe to PyPI and npm security advisories and threat intelligence feeds that track newly registered packages with suspicious characteristics.\n- Establish a process to report confirmed slopsquatting package names to registry security teams (PyPI, npm) for rapid takedown.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SSDF (SP 800-218): PW.4 – Reuse Existing, Well-Secured Software","NIST CSF: ID.SC-3 (Supply Chain Risk Management)","SLSA Framework: Provenance and build integrity requirements","OpenSSF Scorecard: Dependency pinning and CI security checks","OWASP Top 10: A06:2021 – Vulnerable and Outdated Components","NIST AI RMF: GOVERN 1.2 – Trustworthiness of AI outputs","published","2026-07-22T18:22:03.435215+00:00","2026-07-22T18:22:03.135+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fslopsquatting-targets-across-frontier-llms?utm_medium=feed","new-study-identifies-53-slopsquatting-targets-across-5-frontier-llms-8fcc3d","New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]