A 2026 study found nearly one in five AI coding suggestions names a software package that doesn't exist, and attackers are already registering those exact fake names on npm and PyPI before anyone else can.
The Cloud Security Alliance's AI Safety Initiative published a research note on April 19, 2026, after generating 2.23 million code samples across 16 popular code-generating models in Python and JavaScript. Of those samples, 440,445, or 19.7%, contained at least one package name that doesn't actually exist on any registry. Across all the hallucinations, researchers catalogued 205,474 unique fabricated package names. That's not noise. That's a target list, and it's sitting in public research for anyone to read.
Here's the part that turns a quirky AI failure into a real attack surface: when the CSA team reran identical prompts ten times each, 43% of the hallucinated names came back on every single rerun, and 58% showed up more than once. Large language models aren't guessing randomly. They're converging on the same wrong answer, over and over, because of how they've learned to pattern-match plausible-sounding package names from training data. That predictability is the whole vulnerability. An attacker doesn't need to guess what a developer's copilot might suggest. They can run the same prompts themselves, harvest the names that repeat, and register them before a real developer ever does.
Security researchers have a name for this now: slopsquatting, a twist on the old typosquatting trick, except the attacker doesn't need to misspell anything close to a real package. They just need to know what the AI tends to invent.
This isn't theoretical. A package called unused-imports has been sitting on npm, mimicking the real eslint-plugin-unused-imports that developers actually rely on for cleaning up JavaScript imports. Coding assistants, asked to recommend an import-cleanup tool, have been pointing developers straight at the fake one. Even after npm flagged the package as malicious, it kept picking up installs from developers who had no reason to question what their coding assistant handed them. Nobody searched for it. Their AI assistant just handed them the name, and they typed npm install without a second thought.
Google Restricts Its Most Powerful AI Model to Vetted Cyber Defenders First Google launched Gemini 4 Argon on September 30 and gave unrestricted access first to vetted cybersecurity defenders through its Fairwind Program, not to paying customers. The model leads rivals on most disclosed benchmarks but trails Claude Opus 5.5 on coding-agent tasks, and Google says it's gating the release over the model's offensive cyber... - Google restricts Gemini 4 Argon to cyber defenders - how to access Google's Gemini 4 Argon model
That package is tied to a wider campaign security firm Koi Security calls PhantomRaven, active since at least August 2025 and, according to Koi's research, responsible for 126 malicious npm packages and more than 86,000 downloads combined. The trick behind it is what Koi calls Remote Dynamic Dependencies: the package.json looks clean, sometimes containing nothing more than a single console.log line, but it points to a dependency hosted at a plain HTTP URL instead of another npm package. Most registry scanners don't follow raw URLs, so the real payload, a script that harvests npm tokens, GitHub credentials, and CI/CD secrets, loads invisibly at install time. Endor Labs later tracked three more waves of the same campaign between November 2025 and February 2026, adding another 88 packages uploaded through roughly 50 disposable accounts.
Put those two pieces together and the mechanism is straightforward. The CSA's hallucination data gives attackers a ranked list of names large language models are statistically likely to suggest. PhantomRaven, and campaigns like it, show exactly what happens once a fake package with one of those names sits waiting on npm: it collects real downloads from real developers whose only mistake was trusting a tool that's right most of the time.
Frankly, the uncomfortable fact here is that this isn't a bug anyone is going to patch away soon. Hallucination is baked into how these models generate text, predicting the next plausible token, not verifying it against a live registry. Some IDE plugins and package managers have started adding install-time checks against known registries, and a handful of academic groups are working on classifiers that flag suspicious, non-existent package names before a developer ever runs an install command.
Also read: Tencent leases 100,000 AI chips from Oracle in a $7 billion five year deal • Micron posted record AI memory revenue and Wall Street barely blinked • South Korea's chip exports just topped 60 billion dollars in a single month
This article is posted in AI News, check it out for more related stories.
Join the discussion #
Open in the community → Almost there. Sign in and your reply posts straight away.
Three Chinese AI Models Failed Bioweapon Safety Tests in One Month Three Chinese AI Models Failed Bioweapon Safety Tests in One Month - chinese AI models fail bioweapon safety tests - AI jailbreak reveals bioweapon guidance in chinese models