You ask your AI assistant for a quick script. It writes clean code, imports a package you've never heard of, and you run pip install. It installs without errors.
But what if that package didn't exist until last week, and the person who created it wants your API keys?
That's slopsquatting, and it's one of the more interesting security problems of the AI-assisted coding era.
What is slopsquatting?
LLMs sometimes "hallucinate" package names. They recommend a library that sounds perfectly plausible but doesn't exist. Slopsquatting is when an attacker notices these recurring fake names and registers them on a public registry like PyPI or npm, loaded with malicious code.
It's a cousin of typosquatting, where attackers register reqeusts hoping you'll mistype requests. The difference is that here nobody mistypes anything. The model invents the name, and you trust it.
Why this is a real risk, not just a theory
Research on package hallucination in code-generating models (a 2025 study analyzing hundreds of thousands of generated code samples) found three important things:
- Hallucinated packages are common. A meaningful share of recommended packages didn't exist, and open-source models hallucinated more often than commercial ones.
- They're repeatable. Many fake names showed up again and again across runs. That matters because an attacker doesn't need to guess; they can just query models and harvest the popular fake names.
- They look believable. Names usually follow real naming conventions, so they don't trigger your "that looks off" instinct.
Exact rates vary by model, language, and prompt, so treat any single percentage as a snapshot rather than a constant. The pattern is what matters.
How an attack plays out
- An attacker prompts several models with common coding tasks.
- They collect package names that don't exist on the registry.
- They publish malicious packages under those names.
- A developer's AI assistant suggests one of them, and the developer installs it.
- Install scripts or imported code run with the developer's (or CI's) permissions.
Steps 4 and 5 are the dangerous ones. Install-time scripts can run arbitrary code before you've even read a line of the package.
What makes it worse in 2026
Agentic workflows changed the risk profile. When you copy a snippet, a human at least glances at the import. Coding agents that can run shell commands may install dependencies automatically to "make the tests pass." Fewer human checkpoints means fewer chances to catch a bad name.
Parallel agents, CI-triggered agents, and "vibe coding" sessions where nobody reads the dependency list all widen the window.
How to defend yourself
You don't need to stop using AI tools. You need a few habits.
1. Verify before you install
Before adding an unfamiliar dependency, check:
- When was it first published? (A package created last week that your assistant "knows" is suspicious.)
- Download counts and release history
- Linked source repository, and whether the repo is real and active
- Maintainer profile
A 30-second look catches most of this.
2. Pin and lock everything
Use lockfiles (package-lock.json, poetry.lock, requirements.txt with hashes). Hash-pinning in particular means an unexpected package can't silently slip in later.
pip install --require-hashes -r requirements.txt
3. Use an allowlist or private registry
For teams, route installs through an internal proxy (Artifactory, Nexus, or similar) that only permits approved packages. A hallucinated name simply fails to resolve.
4. Disable install scripts where you can
npm config set ignore-scripts true
This won't stop malicious code at import time, but it removes a major execution path during install.
5. Sandbox your agents
Run coding agents in containers or dev environments with no access to production secrets, SSH keys, or cloud credentials. Assume any dependency an agent installs is untrusted until reviewed.
6. Add dependency scanning to CI
Tools like pip-audit, npm audit, Socket, Snyk, and OSV-Scanner flag known-bad and suspicious packages. Make new-dependency diffs a required review item in pull requests.
7. Prompt for existing tools
Ask your assistant to prefer well-known standard-library or already-installed dependencies, and to tell you whenever it introduces a new one. It's not foolproof, but it surfaces additions you'd otherwise miss.
A quick checklist
- [ ] Did the AI add a new dependency?
- [ ] Does the package exist, with real history and a real repo?
- [ ] Is it pinned and locked?
- [ ] Did it run in a sandbox with no secrets?
- [ ] Did CI scan it?
The bigger lesson
Slopsquatting isn't really an AI problem. It's an old trust problem, "I'll run whatever the internet tells me to install," with a new and very persuasive source of suggestions.
AI assistants are great at producing plausible output. Plausible and correct aren't the same thing, and the gap between them is exactly where attackers operate.
Use the tools. Just treat every new dependency like a stranger asking for the keys to your house.
Top comments (0)