Glossary · term

Slopsquatting

Slopsquatting is a software supply-chain attack in which an adversary registers or weaponizes a package name that an AI coding model has invented, expecting a later model recommendation to induce installation. The package hallucination creates the candidate name; adversarial publication and the resulting trust path make it slopsquatting. A nonexistent recommendation by itself is therefore not yet an attack.

Safety2025-04Wave 2 · 2024Maturity: 3/5

Origin and context

Bar Lanyado documented the precursor risk in 2024 and registered an empty `huggingface-cli` package as a benign proof of concept. In April 2025, Seth Larson suggested “slopsquatting” in a conversation with Andrew Nesbitt, who posted it publicly; Socket documented the label and definition the next day. The term is wordplay on AI slop and typosquatting, but it identifies an AI-generated naming signal rather than a human typing error.

Sources: s2, s3, s6

Why it matters

Package installation can execute third-party code with developer, build, or agent privileges. In the USENIX experiment, 440,445 of 2.23 million package recommendations were classified as nonexistent, and 43% of selected hallucinated names recurred in all ten repeated trials. Those figures describe that study, not every model or workflow. A 2026 preprint measured lower rates on newer models but still found shared registrable names, while Trend Micro observed that live validation reduced rather than eliminated phantom dependencies.

Sources: s1, s4, s5

Example

Suppose an assistant repeatedly recommends a plausible but nonexistent package for a routine task. An attacker claims that exact registry name and publishes harmful code; a later user or coding agent trusts the recommendation and installs it. That sequence is slopsquatting. Registering `reqeusts` to catch a person's misspelling is typosquatting. Publishing a public package that overrides an intended private package through resolver behavior is dependency confusion. The mechanisms can overlap, but their initial naming signals differ.

Sources: s1, s2, s3

How it differs

AI hallucination

Package hallucination is the model error that produces a nonexistent dependency name. Slopsquatting is the adversarial supply-chain use of such a name. A hallucination can simply cause an installation failure, and an attacker can squat a name without any proven downstream installation.

AI tool supply-chain attacks

AI tool supply-chain attacks are a broader class that also includes malicious extensions, fake installers, compromised packages, prompt-driven code execution, and MCP infrastructure attacks. Slopsquatting is the narrower package-registry path whose candidate name originates in model output.

Maturity and evidence

Maturity is rated 3. The enabling failure has peer-reviewed USENIX evidence, the exact label received independent early coverage, Trend Micro studied it across coding workflows, and 2026 preprints continued the terminology and replication work. It remains below 4 because the name dates only to 2025, measured rates depend strongly on models and protocols, and controlled attack surfaces are documented more clearly than malicious real-world prevalence.

Sources: s1, s3, s4, s5

Limits and open questions

A registry-existence check is necessary but insufficient: once a name is squatted it exists, and import names may legitimately differ from distribution names. Download counts also mix users, mirrors, scanners, and automated systems, so they do not prove victim compromise. Defenses should verify provenance and maintainer history, constrain allowed registries, pin reviewed dependencies, and isolate installation. No single control or historical hallucination rate guarantees safety for future models.

Sources: s1, s4, s5, s6

Related terms

References

Last updated: 2026-09-05

In the Skills Atlas

This term is also covered in the Skills Atlas as ai supply chain security skill.