<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w" -->

---
title: Slopsquatting: Your AI Invented a Package, and an...
description: AI coding assistants frequently hallucinate package names that don't exist — a USENIX Security 2025 study found 19.7% of packages recommended across 576,000...
canonical: https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Slopsquatting: Your AI Invented a Package, and an Attacker Was Waiting | daily.dev
og:description: AI coding assistants frequently hallucinate package names that don't exist — a USENIX Security 2025 study found 19.7% of packages recommended across 576,000...
og:url: https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w
og:image: https://api.daily.dev/og/posts/pZ8bcRD9w.png
og:image:alt: Slopsquatting: Your AI Invented a Package, and an Attacker Was Waiting
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Slopsquatting: Your AI Invented a Package, and an Attacker Was Waiting

**[DEV](https://daily.dev/sources/devto)** · 9 min read · 4 upvotes · 0 comments

## Summary

AI coding assistants frequently hallucinate package names that don't exist — a USENIX Security 2025 study found 19.7% of packages recommended across 576,000 samples from 16 LLMs were fake, with 205,474 unique hallucinated names. Because 43% of these hallucinations recur consistently on reruns, attackers can predict and pre-register the exact fake names, planting malware that developers unknowingly install. This 'slopsquatting' attack evades typosquatting defenses since most hallucinated names aren't simple misspellings. Newer frontier models show lower rates (4.6%-6.1%) but the risk persists. Defenses include verifying packages before install, pinning/hashing dependencies, using private registries or allow-lists, scanning CI for new dependencies, auditing docs for hallucinated install commands, and gating autonomous agent installs behind human or automated verification.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://dev.to/james_anderson_h/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-1g67>

## Questions this post answers

### What percentage of packages recommended by AI coding assistants don't actually exist?

About 19.7% of packages recommended by large language models are hallucinated and don't exist, based on a USENIX Security 2025 study generating 576,000 code samples across 16 different LLMs. The study logged 205,474 unique non-existent package names. Open-source models hallucinated up to roughly 22% of the time, while GPT-4 Turbo performed best at 3.59%. A 2026 re-evaluation of newer frontier models found rates had narrowed to roughly 4.6%-6.1%.

_Developers vetting AI-suggested dependencies can track slopsquatting research and mitigation tactics on daily.dev._

### Why can attackers exploit AI package hallucinations if the fake names are random?

Hallucinated package names aren't actually random — they're predictable, which is what makes slopsquatting attacks viable. When researchers reran 500 prompts that produced fake packages ten more times each, 43% of the hallucinated names recurred on every single run. A 2026 cross-model study also found 127 package names that five different frontier models invented identically, letting attackers pre-register those exact names with malware.

_Teams building install gates for AI agents can compare defense strategies against slopsquatting on daily.dev._

### Why don't typosquatting detection tools catch slopsquatted packages?

Typosquatting detection relies on string similarity, checking how many character edits separate a suspicious name from a real package, but slopsquatted names usually aren't typos. Research found only about 13% of hallucinated package names were simple typos of real ones; nearly half were wildly dissimilar to anything that exists, so names like aws-helper-sdk sound plausible without resembling any real package closely enough to trigger a similarity check.

_Developers hardening CI pipelines against novel dependency risks can follow ongoing coverage on daily.dev._

## Similar posts on daily.dev

- [New Study Identifies 53 Slopsquatting Targets Across 5 Front...](https://daily.dev/posts/new-study-identifies-53-slopsquatting-targets-across-5-front--6t7a1jnzb) · Socket · 0 upvotes · 0 comments
- [‘HalluSquatting’ Compromises AI Coding Agents to Install Malware, Create Botnets](https://daily.dev/posts/hallusquatting-compromises-ai-coding-agents-to-install-malware-create-botnets-qkcjydbad) · DevOps.com · 2 upvotes · 1 comments
- [Prevent AI Package Hallucination Attacks in CI/CD](https://daily.dev/posts/prevent-ai-package-hallucination-attacks-in-ci-cd-j6zbr4wkf) · SitePoint · 0 upvotes · 0 comments
- [Hackers can use 9 of the most popular AI tools to assemble massive botnets](https://daily.dev/posts/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets-j8cybjfqg) · Ars Technica · 13 upvotes · 4 comments

---

Tags: [#ai](https://daily.dev/tags/ai), [#security](https://daily.dev/tags/security), [#webdev](https://daily.dev/tags/webdev), [#ai-coding](https://daily.dev/tags/ai-coding)

[View this post on daily.dev](https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Slopsquatting: Your AI Invented a Package, and an Attacker Was Waiting","url":"https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w"},"datePublished":"2026-09-30T18:39:02.941Z","dateModified":"2026-09-30T18:39:27.999Z","description":"AI coding assistants frequently hallucinate package names that don't exist — a USENIX Security 2025 study found 19.7% of packages recommended across 576,000...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/55c33404ca85895368e9f746e80ea6dc?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/55c33404ca85895368e9f746e80ea6dc?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"DEV","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"DEV","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/devto","url":"https://daily.dev/sources/devto"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":4},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai,security,webdev,ai-coding","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"DEV","item":"https://daily.dev/sources/devto"},{"@type":"ListItem","position":3,"name":"Slopsquatting: Your AI Invented a Package, and an Attacker Was Waiting"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/slopsquatting-your-ai-invented-a-package-and-an-attacker-was-waiting-pz8bcrd9w#faq","mainEntity":[{"@type":"Question","name":"What percentage of packages recommended by AI coding assistants don't actually exist?","acceptedAnswer":{"@type":"Answer","text":"About 19.7% of packages recommended by large language models are hallucinated and don't exist, based on a USENIX Security 2025 study generating 576,000 code samples across 16 different LLMs. The study logged 205,474 unique non-existent package names. Open-source models hallucinated up to roughly 22% of the time, while GPT-4 Turbo performed best at 3.59%. A 2026 re-evaluation of newer frontier models found rates had narrowed to roughly 4.6%-6.1%. Developers vetting AI-suggested dependencies can track slopsquatting research and mitigation tactics on daily.dev."}},{"@type":"Question","name":"Why can attackers exploit AI package hallucinations if the fake names are random?","acceptedAnswer":{"@type":"Answer","text":"Hallucinated package names aren't actually random — they're predictable, which is what makes slopsquatting attacks viable. When researchers reran 500 prompts that produced fake packages ten more times each, 43% of the hallucinated names recurred on every single run. A 2026 cross-model study also found 127 package names that five different frontier models invented identically, letting attackers pre-register those exact names with malware. Teams building install gates for AI agents can compare defense strategies against slopsquatting on daily.dev."}},{"@type":"Question","name":"Why don't typosquatting detection tools catch slopsquatted packages?","acceptedAnswer":{"@type":"Answer","text":"Typosquatting detection relies on string similarity, checking how many character edits separate a suspicious name from a real package, but slopsquatted names usually aren't typos. Research found only about 13% of hallucinated package names were simple typos of real ones; nearly half were wildly dissimilar to anything that exists, so names like aws-helper-sdk sound plausible without resembling any real package closely enough to trigger a similarity check. Developers hardening CI pipelines against novel dependency risks can follow ongoing coverage on daily.dev."}}]}
```

