What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Slopsquatting

Slopsquatting is a supply chain attack that exploits large language models' tendency to hallucinate package names that do not exist. An attacker pre-registers a hallucinated name on npm, PyPI or another registry with a malicious payload, then waits for a developer or agent to install it unverified. Seth Larson coined the term in April 2025, blending "AI slop" and "typosquatting".

Last reviewed

Key points

  • Slopsquatting exploits AI hallucinations, not human typos: an LLM invents a package name that never existed, and an attacker registers it first.
  • The 2025 USENIX Security study found 19.7% of AI-recommended packages did not exist across 576,000 code samples, yielding 205,000 unique hallucinated names; when 500 hallucination-triggering prompts were re-run ten times each, 43% of the hallucinated names recurred on every run — making the attack economic.
  • Traditional registry defences miss it because only 13.4% of hallucinated names are within Levenshtein distance 1-2 of a real package; 48.6% are at distance 6 or more.
  • The 2026 HalluSquatting escalation eliminated the human review step: autonomous AI coding agents now install hallucinated packages without a developer ever seeing the name, turning slopsquatting from a passive install risk into an active RCE vector.
  • Hallucination rates vary sharply by model: open-source models hallucinate at 21.7% on average versus 5.2% for proprietary models, making organizations using open-source tools roughly four times more exposed.

When an AI recommends a package name, it is a statistical guess. Slopsquatting exploits the gap between that confidence and the fact that many of those guesses have no corresponding real package.

How it works

An LLM references a package that does not exist. An attacker observes this at scale, identifies which names recur, and registers them with a malicious payload before anyone else does. The next developer or agent asking the same question installs the hallucinated name and runs the attacker’s code.

The 2025 USENIX Security paper by Spracklen et al. tested 16 models across 576,000 code samples and found 19.7% of recommended packages did not exist — 205,000 unique hallucinated names. Open-source models hallucinated at 21.7% versus 5.2% for proprietary models. Re-running prompts ten times each, 43% of hallucinated names appeared on every run and 58% recurred more than once, repeatable enough to enumerate.

Only 13.4% of hallucinated names were within Levenshtein distance 1-2 of a real package; 48.6% were at distance 6 or more, far from anything registered. Typosquatting detectors key off small edit distance from popular names — the wrong shape for confident inventions rather than misspellings.

HalluSquatting

In July 2026, researchers extended slopsquatting into repositories and agent skill files, pairing registration with prompt injection that hijacks an agent’s terminal on fetch — RCE through the agent’s own permissions. Hallucination rates reached 85% for repository-cloning prompts and 100% for agent skill installations. In January 2026, Aikido Security found a hallucinated package, react-codeshift, spread to 237 repositories via agent skill files, with agents installing it daily; the researcher registered it defensively.

Questions and answers

How is slopsquatting different from typosquatting?

Typosquatting relies on a human mistyping a real package name — changing a letter or dropping a character. Slopsquatting relies on an AI inventing a name that never existed. The USENIX 2025 study found only 13.4% of hallucinated names were within Levenshtein distance 1-2 of a real package; 48.6% were at distance 6 or greater. Traditional registry-side typosquatting detectors key off small edit distance from popular names, which is exactly the wrong shape for this threat.

Why do hallucinations recur enough to make this attack work?

When the same prompts are re-run, 43% of hallucinated package names appear on every single attempt and 58% recur more than once. The researchers describe "an unexpected dichotomy": most hallucinated names either recur on all ten runs or never recur, and the stable ones are the ones attackers can enumerate and register. An attacker does not need to brute-force names; they observe model behavior, note the names that keep recurring, and register them.

What changed in 2026?

Autonomous AI coding agents eliminated the human review step. In the 2025 pattern, a developer had to copy-paste or approve the hallucinated package installation — at least an implicit checkpoint. The HalluSquatting research demonstrated that agents install hallucinated packages without the developer ever seeing the name, and that combining the squatting with prompt injection payloads can achieve remote code execution through the agent's own terminal access. Hallucination rates reached 85% for repository-cloning prompts and 100% for agent skill installations.

Are certain models more vulnerable than others?

Open-source models hallucinate roughly four times more than proprietary ones. The USENIX study found 21.7% average hallucination rates for open-source models versus 5.2% for commercial models. GPT-4 Turbo had the lowest rate, 3.59% on Python. Churilov's 2026 study found 127 names hallucinated identically across five different frontier models from different vendors, suggesting the problem is systemic across current architectures.

What should organizations do about it?

The CSA recommends treating every AI-generated package reference as untrusted input. Verify each against the target registry before installation. Enforce lockfile pinning and hash verification across all CI/CD pipelines. Prohibit AI agents from installing packages without human review or an allowlist gate. Produce SBOMs for all AI-generated codebases. Configure software composition analysis tools to flag packages registered within the prior 30-90 days. Treat any package recommended by an AI model the same as an untrusted third-party component.

Sources

  1. Socket, "The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain Attacks" (2025-04-08)Socket, 8 Apr 2025
  2. Wikipedia, Slopsquatting (retrieved 2026-09-15)Wikipedia, 14 Jul 2026
  3. Spracklen et al., "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs" (USENIX Security 2025, arXiv:2406.10279)USENIX Security 2025, 12 Jun 2024
  4. Lanyado, "Can you trust ChatGPT's package recommendations?" (2023-06-06)Vulcan / Lasso Security, 6 Jun 2023
  5. Cloud Security Alliance, "Slopsquatting: AI Code Hallucinations Fuel Supply Chain Attacks" (2026-04-19)Cloud Security Alliance, 19 Apr 2026
  6. Eriksen, "Agent Skills Are Spreading Hallucinated npx Commands" (2026-01-21)Aikido Security, 21 Jan 2026
  7. Cloud Security Alliance, "HalluSquatting: AI Hallucinations Weaponized for Botnet Delivery" (2026-07-12)Cloud Security Alliance, 12 Jul 2026
  8. Lutkevich, "Slopsquatting explained: When AI code turns malicious" (2026-09-04)TechTarget, 4 Sep 2026
  9. KnowBe4, "Warning: Slop Squatting Directs AI Users to Phishing Pages" (2026-09-14)KnowBe4, 14 Sep 2026
  10. Churilov, "The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort" (preprint, cited 2026-07-24)Research preprint, cited by Cisco SMB, 24 Jul 2026
  11. MITRE ATLAS, AML.T0011.000 and AML.T0010.005 (collection 2026.08)MITRE

Guides that use this term