Slopsquatting
Slopsquatting is a software supply-chain attack in which an adversary registers or weaponizes a package name that an AI coding model has invented, expecting a later model recommendation to induce installation. The package hallucination creates the candidate name; adversarial publication and the resulting trust path make it slopsquatting. A nonexistent recommendation by itself is therefore not yet an attack.
Origin and context
Bar Lanyado documented the precursor risk in 2024 and registered an empty `huggingface-cli` package as a benign proof of concept. In April 2025, Seth Larson suggested “slopsquatting” in a conversation with Andrew Nesbitt, who posted it publicly; Socket documented the label and definition the next day. The term is wordplay on AI slop and typosquatting, but it identifies an AI-generated naming signal rather than a human typing error.
Why it matters
Package installation can execute third-party code with developer, build, or agent privileges. In the USENIX experiment, 440,445 of 2.23 million package recommendations were classified as nonexistent, and 43% of selected hallucinated names recurred in all ten repeated trials. Those figures describe that study, not every model or workflow. A 2026 preprint measured lower rates on newer models but still found shared registrable names, while Trend Micro observed that live validation reduced rather than eliminated phantom dependencies.
Example
Suppose an assistant repeatedly recommends a plausible but nonexistent package for a routine task. An attacker claims that exact registry name and publishes harmful code; a later user or coding agent trusts the recommendation and installs it. That sequence is slopsquatting. Registering `reqeusts` to catch a person's misspelling is typosquatting. Publishing a public package that overrides an intended private package through resolver behavior is dependency confusion. The mechanisms can overlap, but their initial naming signals differ.
How it differs
AI hallucination
Package hallucination is the model error that produces a nonexistent dependency name. Slopsquatting is the adversarial supply-chain use of such a name. A hallucination can simply cause an installation failure, and an attacker can squat a name without any proven downstream installation.
AI tool supply-chain attacks
AI tool supply-chain attacks are a broader class that also includes malicious extensions, fake installers, compromised packages, prompt-driven code execution, and MCP infrastructure attacks. Slopsquatting is the narrower package-registry path whose candidate name originates in model output.
Maturity and evidence
Maturity is rated 3. The enabling failure has peer-reviewed USENIX evidence, the exact label received independent early coverage, Trend Micro studied it across coding workflows, and 2026 preprints continued the terminology and replication work. It remains below 4 because the name dates only to 2025, measured rates depend strongly on models and protocols, and controlled attack surfaces are documented more clearly than malicious real-world prevalence.
Limits and open questions
A registry-existence check is necessary but insufficient: once a name is squatted it exists, and import names may legitimately differ from distribution names. Download counts also mix users, mirrors, scanners, and automated systems, so they do not prove victim compromise. Defenses should verify provenance and maintainer history, constrain allowed registries, pin reviewed dependencies, and isolate installation. No single control or historical hallucination rate guarantees safety for future models.
Related terms
References
- We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs34th USENIX Security Symposium · 2025-08 · class A
- Slopsquatting meets Dependency ConfusionAndrew Nesbitt · 2025-12-10 · class B
- The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain AttacksSocket · 2025-04-08 · class B
- Slopsquatting: When AI Agents Hallucinate Malicious PackagesTrend Micro Research · 2025-06-05 · class B
- The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model CohortAleksandr Churilov / arXiv · 2026-05-16 · class A
- Diving Deeper into AI Package HallucinationsLasso Security · 2024-03-28 · class B
- AI Developer Tool Supply Chain Attacks: RCE, Fake Installers, and AI-Promoted Malicious ReposCloud Security Alliance AI Safety Initiative · 2026-03-08 · class B
Last updated: 2026-09-05
This term is also covered in the Skills Atlas as ai supply chain security skill.