<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv" -->

---
title: Who Vets AI’s Code? The Scale Challenge Facing Open...
description: AI coding assistants can suggest package names that don&#x27;t exist in registries like PyPI or npm, a vulnerability called slopsquatting, where attackers register...
canonical: https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion | daily.dev
og:description: AI coding assistants can suggest package names that don&#x27;t exist in registries like PyPI or npm, a vulnerability called slopsquatting, where attackers register...
og:url: https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv
og:image: https://api.daily.dev/og/posts/KrGDFWRVv.png
og:image:alt: Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 6 min read · 0 upvotes · 0 comments

## Summary

AI coding assistants can suggest package names that don't exist in registries like PyPI or npm, a vulnerability called slopsquatting, where attackers register these hallucinated names and upload malicious payloads. A USENIX Security study of sixteen code-generation models across 500,000+ samples found many AI-suggested packages don't exist, and nearly half of those that do resolve contain known CVEs. A tracked incident involved a hallucinated npm package spreading through 47 AI agent skills into 230+ repositories via forks. Major projects like Kubernetes, Linux kernel, LLVM, and Godot have diverging AI contribution policies, and a CodeRabbit review found AI-co-authored PRs had 70% more defects than human-authored code. The piece, sponsored by ActiveState, argues security teams should govern package ingestion at the point of selection rather than relying on post-commit scans, and promotes ActiveState's curated catalog as a solution claiming roughly 95% CVE exposure reduction.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion>

## Questions this post answers

### What is slopsquatting in AI-generated code?

Slopsquatting is a supply-chain attack where an AI coding assistant hallucinates a package name that doesn't actually exist in a registry like PyPI or npm, and an attacker registers that exact name with a malicious payload, waiting for developer tools or CI/CD pipelines to fetch it automatically. A USENIX Security study analyzing over 500,000 code samples across sixteen code-generation models found this to be a measurable, exploitable pattern.

_Developers weighing AI-assisted coding risk factors follow supply-chain issues like slopsquatting on daily.dev._

### How much more error-prone is AI-co-authored code in open source pull requests compared to human-written code?

A CodeRabbit review of 470 open-source pull requests found AI-co-authored contributions carried 70% more defects than human-authored code, even though the code often reads clean on the surface. This creates added burden for volunteer maintainers who must validate dependencies and changes that no human deliberately reviewed.

_Teams deciding how much to trust AI pull requests can track findings like this on daily.dev._

### How did a hallucinated npm package spread through open source repositories before being caught?

A hallucinated npm package name, react-codeshift, originated from 47 AI-generated agent skills in a single commit and spread organically through forks into more than 230 repositories before an engineer noticed no human had ever explicitly selected it. The absence of ingestion controls, not malicious intent, allowed the hallucinated dependency to propagate.

_Anyone auditing AI-introduced dependencies can follow real incidents like this via daily.dev._

## Similar posts on daily.dev

- [New Study Identifies 53 Slopsquatting Targets Across 5 Front...](https://daily.dev/posts/new-study-identifies-53-slopsquatting-targets-across-5-front--6t7a1jnzb) · Socket · 0 upvotes · 0 comments
- [Supply-chain attacks take aim at your AI coding agents](https://daily.dev/posts/supply-chain-attacks-take-aim-at-your-ai-coding-agents-o8vsjrfrt) · CSO Online · 0 upvotes · 0 comments
- [Report: AI hallucinates 27% of upgrade recommendations for open source projects](https://daily.dev/posts/report-ai-hallucinates-27-of-upgrade-recommendations-for-open-source-projects-9sgp9ienu) · SD Times · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#ai-coding](https://daily.dev/tags/ai-coding)

[View this post on daily.dev](https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion","url":"https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv"},"datePublished":"2026-08-13T14:01:27.574Z","dateModified":"2026-09-14T06:42:38.674Z","description":"AI coding assistants can suggest package names that don't exist in registries like PyPI or npm, a vulnerability called slopsquatting, where attackers register...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/67557149005d2e73b70ddc5e2da727d3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/67557149005d2e73b70ddc5e2da727d3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,ai-coding","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/who-vets-ai-s-code-the-scale-challenge-facing-open-source-ingestion-krgdfwrvv#faq","mainEntity":[{"@type":"Question","name":"What is slopsquatting in AI-generated code?","acceptedAnswer":{"@type":"Answer","text":"Slopsquatting is a supply-chain attack where an AI coding assistant hallucinates a package name that doesn't actually exist in a registry like PyPI or npm, and an attacker registers that exact name with a malicious payload, waiting for developer tools or CI/CD pipelines to fetch it automatically. A USENIX Security study analyzing over 500,000 code samples across sixteen code-generation models found this to be a measurable, exploitable pattern. Developers weighing AI-assisted coding risk factors follow supply-chain issues like slopsquatting on daily.dev."}},{"@type":"Question","name":"How much more error-prone is AI-co-authored code in open source pull requests compared to human-written code?","acceptedAnswer":{"@type":"Answer","text":"A CodeRabbit review of 470 open-source pull requests found AI-co-authored contributions carried 70% more defects than human-authored code, even though the code often reads clean on the surface. This creates added burden for volunteer maintainers who must validate dependencies and changes that no human deliberately reviewed. Teams deciding how much to trust AI pull requests can track findings like this on daily.dev."}},{"@type":"Question","name":"How did a hallucinated npm package spread through open source repositories before being caught?","acceptedAnswer":{"@type":"Answer","text":"A hallucinated npm package name, react-codeshift, originated from 47 AI-generated agent skills in a single commit and spread organically through forks into more than 230 repositories before an engineer noticed no human had ever explicitly selected it. The absence of ingestion controls, not malicious intent, allowed the hallucinated dependency to propagate. Anyone auditing AI-introduced dependencies can follow real incidents like this via daily.dev."}}]}
```

