<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k" -->

---
title: The npm package your AI just suggested doesn&#x27;t exist....
description: New USENIX Security 2025 research reveals ~19.7% of packages recommended by AI coding assistants are hallucinated, and attackers are exploiting this by...
canonical: https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The npm package your AI just suggested doesn&#x27;t exist. Someone already registered it with malware. | daily.dev
og:description: New USENIX Security 2025 research reveals ~19.7% of packages recommended by AI coding assistants are hallucinated, and attackers are exploiting this by...
og:url: https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k
og:image: https://api.daily.dev/og/posts/IRcLbQu0k.png
og:image:alt: The npm package your AI just suggested doesn&#x27;t exist. Someone already registered it with malware.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The npm package your AI just suggested doesn't exist. Someone already registered it with malware.

**[Cyber Security](https://daily.dev/sources/cyber_sec)** · [@julia7](https://daily.dev/julia7) · 2 min read · 0 upvotes · 0 comments

## Summary

New USENIX Security 2025 research reveals ~19.7% of packages recommended by AI coding assistants are hallucinated, and attackers are exploiting this by registering those predictable fake package names on npm and PyPI with malicious code — a technique called 'slopsquatting'. One planted proof-of-concept package accumulated 30,000+ downloads in three months. Over 450,000 new malicious packages were published in 2025 alone, a 75% YoY increase, making signature-based scanning insufficient. The post promotes a free live session on July 22nd covering AI Bill of Materials and behavior-based detection strategies.

## Content

New research (USENIX Security 2025) found that ~19.7% of packages recommended by AI coding assistants are pure hallucination. The interesting part isn't the hallucination itself; it's that the same fake package names come back predictably across sessions and models.

Attackers noticed this and started registering those exact hallucinated names on public registries, shipping malicious code inside, and waiting for the next `pip install` or `npm install`. The technique now has a name: **slopsquatting**.

Some numbers worth knowing:

- A single hallucinated package, planted as a benign proof-of-concept, pulled **30,000+ downloads in three months**
- Confirmed malicious packages exploiting this exact pattern are already live in public registries
- **450,000+ new malicious packages** were published in 2025 alone (~75% YoY growth), which is why signature-based scanning structurally can't keep pace
- With AI now generating a large share of production code, every hallucinated suggestion is a potential entry point

We're running a free, live technical session on July 22nd, showing the actual detection mechanics: how to build an AI Bill of Materials to map every AI component in a stack, and how behavior-based detection catches malicious packages before a signature exists for them.

If anyone's into this space, more than welcome to join ➡️ [https://www.linkedin.com/events/7480522038990979074/](https://www.linkedin.com/events/7480522038990979074/)

𝐘𝐨𝐮 𝐜𝐚𝐧'𝐭 𝐝𝐞𝐟𝐞𝐧𝐝 𝐰𝐡𝐚𝐭 𝐲𝐨𝐮 𝐜𝐚𝐧'𝐭 𝐬𝐞𝐞.

---

Tags: [#security](https://daily.dev/tags/security), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k","headline":"The npm package your AI just suggested doesn't exist. Someone already registered it with malware.","text":"New USENIX Security 2025 research reveals ~19.7% of packages recommended by AI coding assistants are hallucinated, and attackers are exploiting this by registering those predictable fake package names on npm and PyPI with malicious code — a technique called 'slopsquatting'. One planted proof-of-concept package accumulated 30,000+ downloads in three months. Over 450,000 new malicious packages were published in 2025 alone, a 75% YoY increase, making signature-based scanning insufficient. The post promotes a free live session on July 22nd covering AI Bill of Materials and behavior-based detection strategies.","url":"https://daily.dev/posts/the-npm-package-your-ai-just-suggested-doesn-t-exist-someone-already-registered-it-with-malware--irclbqu0k","datePublished":"2026-07-09T05:55:21.481Z","dateModified":"2026-07-09T05:55:35.252Z","author":{"@type":"Person","name":"Julia","url":"https://daily.dev/julia7","image":"https://media.daily.dev/image/upload/s--Vye82kCe--/f_auto/v1752235114/avatars/avatar_JI6NHO2CHs2BU4FFm4NUw?_a=BAMClqZW0","description":"DevSecOps Lover and Software Supply Chain Security Advocate | Solutions Manager at Xygeni","interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"EndorseAction"},"userInteractionCount":240}},"image":"https://media.daily.dev/image/upload/s--46e1rEyJ--/f_auto/v1783501432/posts/NX4gAswyi?_a=BAMAMicg0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/squads/cyber_sec","name":"Cyber Security"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Cyber Security","item":"https://daily.dev/squads/cyber_sec"},{"@type":"ListItem","position":3,"name":"The npm package your AI just suggested doesn't exist. Someone already registered it with malware."}]}
```

