Slopsquatting is a newly identified supply chain attack that exploits how large language model AI coding assistants hallucinate fake software package names.
Attackers then register those fabricated packages and fill them with malicious code, allowing developers who follow the AI suggestions to unknowingly introduce compromised dependencies into their projects from day one.
What happened
A new attack method called slopsquatting exploits how AI coding assistants generate fictitious software package names. Threat actors register those fake package names and populate them with malicious code, which developers unknowingly install when they follow the AI-suggested code.
Why it matters
As developers increasingly rely on AI coding assistants, they may grant cybercriminals access to their software from the start of development. This attack vector is distinct from traditional typosquatting because it leverages LLM hallucinations rather than human mistakes.
What to watch
The risk expands as AI-assisted coding becomes standard practice. Developers should be aware that LLMs can generate fictitious open-source packages, which threat actors can then weaponize.
Ask the AI about this article →
Slopsquatting represents an emerging class of supply chain threat enabled by the widespread adoption of AI coding assistants. Unlike traditional typosquatting, which depends on human typographical errors or inattention, slopsquatting exploits a fundamental characteristic of large language models: their tendency to generate plausible-sounding but entirely fictitious package names. The attack is particularly insidious because developers trust the code suggestions generated by their AI tools, making them unlikely to scrutinize whether a package name is real.
The threat model is straightforward but effective. When an LLM suggests a nonexistent open-source package during a coding session, developers may install it without verification. If a threat actor has already registered that exact fictitious package name and seeded it with malicious code, the developer's system becomes compromised from the outset. This grants attackers early and deep access to the software supply chain, potentially affecting not only the initial developer but also downstream users of any code or product built on the compromised foundation.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
John Ternus takes over as CEO of Apple today, stepping into the role as the company confronts the AI era

Top AI-native open source projects like Flue and tldraw are refusing external pull requests, often because the…

Google DeepMind chief Koray Kavukcuoglu said being at the frontier of AI is the only thing that matters to the…

John Deere is testing an AI assistant called “JD” that answers farmers' questions on topics like equipment set…

Google has launched Google Pics, a new suite of creative design tools for Workspace users, built around Gemini…

OpenAI said today that it is integrating ChatGPT Health with Epic's electronic health record (EHR) system, whi…
