It's 2 a.m. and I'm not hacking anything. I'm watching a list.
The list is made of package names that don't exist, recommended to thousands of developers by an assistant that sounds very sure of itself. All I have to do is register one of them and wait.
I don't need a zero-day. I don't need to phish anyone. The developer will install my code for me, because their AI told them to.
So I ran the experiment from the defender's side. How long would that list be?
Slopsquatting in 30 seconds
An AI coding tool suggests a package that doesn't exist. An attacker registers that exact name on npm or PyPI and puts something nasty inside. A developer copies the install command, and it works.
The term was coined by Seth Larson of the Python Software Foundation. It differs from typosquatting in one important way: no human makes a typo. The model makes the mistake, confidently.
Why I wanted my own numbers
Most posts on this topic are explainers or quote someone else's statistic. One recent preprint (not yet peer-reviewed) reported that five different LLMs invented the same 127 package names. If hallucinations repeat across models, they're predictable, and predictable means targetable.
It also means you can test it yourself. So I did.
The experiment
- Tools tested: Claude (Haiku 4.5), GitHub Copilot (auto/default model), ChatGPT / Codex (Codex default)
- Prompts: 30 everyday tasks, such as "parse a PDF", "validate an email", "rate-limit an API" (ecosystem: npm / JavaScript)
- Method: I extracted every package each tool suggested and checked whether it exists on the registry using a small script of my own that looked up each name on the npm registry
- Limit: 30 prompts is a small sample, so read these numbers as a signal, not a verdict.
- Safety rule: I never installed a package that failed the check. I only looked it up.
Results
| Tool | Fake packages found |
|---|---|
| Claude (Haiku 4.5) | 2 |
| GitHub Copilot (auto) | 1 |
| ChatGPT / Codex | 3 |
Across 30 prompts, the three tools made 6 fake package suggestions that don't exist on npm (counted per tool).
Overlap: 2 of those fake names showed up in more than one tool.
Suspicious but real: 2 packages existed but were very new or had almost no downloads. "It exists" is not the same as "it's safe." A package someone registered last week can be exactly what an attacker wants you to find.
I'm deliberately not publishing the fake names. A list of unregistered, AI-popular package names is a shopping list for attackers.
The part that surprised me
Two fake names appeared in more than one tool.
I expected noise. If each tool were simply guessing, two different products independently inventing the same nonexistent package should be rare. It happened twice in 30 prompts.
That's what turns a glitch into a pattern. A random mistake is hard to exploit. A repeatable one is a target.
So, hype or real?
Real, but not apocalyptic.
Six fake suggestions across 30 prompts is not a flood. Most of what these tools recommended was real, and my sample is small. But an attack like this only needs one hit:
- An AI invents a plausible name.
- Someone registers it before you do.
- A developer installs it without looking.
The two names that appeared in more than one tool are the ones I'd worry about, because repetition is what makes a hallucination worth squatting on. And the two suspicious-but-real packages show the second layer: even a successful lookup doesn't tell you who is behind the package.
A 5-minute defence checklist
- Never paste an AI-suggested install command blind. Look the package up first.
- Check age, downloads and repo link.
# npm: creation date and maintainers
npm view <package> time.created maintainers
# PyPI: metadata and release history
curl -s https://pypi.org/pypi/<package>/json | head -c 600
- Treat "new and unknown" as untrusted. A package created last week with a handful of downloads deserves a manual read.
- Commit your lockfile and review dependency diffs in PRs like you review code.
- Add a dependency scanner to CI so a bad name gets flagged before it ships.
A moment from my own test: one of the fake names looked so real that I didn't doubt it for a second. Nothing about it felt off. The registry lookup was the only thing that caught it. My instincts didn't.
Your turn
My process is the checklist above, and it only exists because one fake name in my test looked so real that my own instincts didn't flag it. The lookup did.
What's yours? How does your team check AI-suggested dependencies before they get installed: a process, a tool, or just trust?
Drop it in the comments. I'll collect the best answers into a follow-up.
Top comments (0)