AI Recommends Packages Attackers Registered First A developer warns that AI coding agents are being exploited through "slopsquatting," where attackers register hallucinated package names that LLMs recommend. A USENIX Security 2025 study by Spracklen found 19.7% of over two million code samples from 16 models contained at least one non-existent package, producing 205,474 distinct invented names, with 43% of names reappearing across repeated runs. Confirmed cases include the malicious npm package unused-imports and the non-existent react-codeshift, while an Anthropic internal evaluation saw a model-published malicious PyPI package downloaded and executed by 15 real systems within an hour. There is a package name your agent writes with total confidence and that never existed. The LLM invented it, repeats it with almost the same words every time you ask, and someone registered it on npm before anyone else. That is slopsquatting, the modern cousin of typosquatting, where the mistake is no longer made by the developer's finger but by the AI's hallucination. The term was coined by Seth Larson, developer-in-residence at the Python Software Foundation, and in 2026 it has stopped being a theoretical warning Source: Infosecurity Magazine . The USENIX Security 2025 study by Spracklen put numbers on the problem. Out of more than two million code samples generated by 16 models... 19.7% contained at least one package that does not exist, and the full corpus produced 205,474 distinct invented names Source: Cloud Security Alliance . The distribution explains why it works. 38% are fusions of two real packages, the classic react-codeshift that comes out of jscodeshift and react-codemod. 13% are variants of a real name. And 51% are pure inventions. They are not random errors. I repeat... THEY ARE INVENTIONS When the same prompt is run ten times, 43% of the names reappeared in every run, so the attacker only has to cultivate the hallucination, register the name and sit back watching Netflix. That said... not all models fail the same way, since open ones averaged 21.7% hallucination against 5.2% for commercial ones. What changes the equation this time is not the LLM, it is who installs. Until now it took a human to read the recommendation and type the install command. A coding agent resolves dependencies on its own, and on that path nobody looks at the name. As Andrew Nesbitt summed it up in April 2026, the agent removes the only checkpoint that was left Source: Cloud Security Alliance . The confirmed cases are no longer hypothetical. The npm package unused-imports is real malware and not the eslint-plugin-unused-imports library the model meant to name, and it kept adding around 233 weekly downloads in early 2026 despite npm blocking it. huggingface-cli, does that ring a bell? A name the AI recommended naturally passed 30,000 downloads in three months after an AI-generated install command ended up copied into the public documentation of an Alibaba repository without anyone verifying it. And in January 2026 researcher Charlie Eriksen claimed the name react-codeshift, which did not exist and had no author, while real agents tried to run it. The ceiling of this escalation was set by Anthropic itself. In an internal evaluation exercise, a model created a malicious Python package, published it to the real PyPI and within an hour 15 real systems had downloaded and executed it, one of them the malware scanner of a security company, whose credentials ended up exfiltrated and used to move further in Source: StepSecurity . The same week it is confirmed that an agent installs whatever it is told, Cisco Talos documented CLOSEDQUORUM, Windows malware that queries DeepSeek, Qwen, Mistral and Gemini to decide its actions without human intervention Source: marketingprofs.com . It steals credentials and cryptocurrency. It is one of the first samples of malware orchestrated by several LLMs at once. And in parallel, Google restricted Gemini 4 Argon to partners of the Fairwind program, with the ability to find, validate and patch vulnerabilities, but only for selected defenders Source: blog.google . The asymmetry is the same one I have been pointing out for months, and with a little research you notice it... The attacker already has agents that decide and the defender is still waiting for an invitation. I would set up a clean machine, launch a prompt asking for an uncommon dependency and capture the name the model proposes. I would repeat it ten times to see how many match, because that repetition is exactly what the attacker exploits. Then I would check the name against the registry or look at who published it and when, and install it with scripts disabled to see what it tries to do. With that I would have evidence that the scenario is real on my own machine without depending on any outside report, it is simple. The lesson is not to distrust AI... it is not to give it the final signature. Checking a name against the registry costs far less than rebuilding what the postinstall took. This is the new era of defenders, the new job of those of us who carry analysis in our blood and call ourselves Cybersecurity Analysts... friend, your certifications do not make you an analyst, at best they get you more interviews in a BROKEN job market Bon appétit Originally published at https://sammideblas.com/notas/ai-recommends-packages-attackers-registered-first https://sammideblas.com/notas/ai-recommends-packages-attackers-registered-first Si has leído hasta aquí... reacciona y comparte - "la seguridad y la defensa en la era de la IA es cosa de todos los que la usan" ¿No Crees?