cd /news/ai-tools/i-tested-3-ai-coding-tools-for-slops… · home › topics › ai-tools › article
[ARTICLE · art-146371] src=dev.to ↗ pub= topic=ai-tools verified=true sentiment=↓ negative

I Tested 3 AI Coding Tools for Slopsquatting. Here's How Many Fake Packages They Invented.

A developer tested three AI coding assistants across 30 prompts and found they suggested six nonexistent package names, with two fake names appearing in more than one tool — a pattern the author says makes "slopsquatting" attacks predictable and targetable. The experiment also surfaced two real but very new, low-download packages, which the author notes can be just as risky as fabricated ones. The developer withheld the fake names to avoid handing attackers a shopping list, and published registry-lookup commands (npm view, PyPI JSON API) as a verification step.

by read3 min views2 publishedOct 6, 2026

It's 2 a.m. and I'm not hacking anything. I'm watching a list.

The list is made of package names that don't exist, recommended to thousands of developers by an assistant that sounds very sure of itself. All I have to do is register one of them and wait.

I don't need a zero-day. I don't need to phish anyone. The developer will install my code for me, because their AI told them to.

So I ran the experiment from the defender's side. How long would that list be?

An AI coding tool suggests a package that doesn't exist. An attacker registers that exact name on npm or PyPI and puts something nasty inside. A developer copies the install command, and it works.

The term was coined by Seth Larson of the Python Software Foundation. It differs from typosquatting in one important way: no human makes a typo. The model makes the mistake, confidently.

Most posts on this topic are explainers or quote someone else's statistic. One recent preprint (not yet peer-reviewed) reported that five different LLMs invented the same 127 package names. If hallucinations repeat across models, they're predictable, and predictable means targetable.

It also means you can test it yourself. So I did.

Tool Fake packages found
Claude (Haiku 4.5) 2
GitHub Copilot (auto) 1
ChatGPT / Codex 3

Across 30 prompts, the three tools made 6 fake package suggestions that don't exist on npm (counted per tool).

Overlap: 2 of those fake names showed up in more than one tool.

Suspicious but real: 2 packages existed but were very new or had almost no downloads. "It exists" is not the same as "it's safe." A package someone registered last week can be exactly what an attacker wants you to find.

I'm deliberately not publishing the fake names. A list of unregistered, AI-popular package names is a shopping list for attackers.

Two fake names appeared in more than one tool.

I expected noise. If each tool were simply guessing, two different products independently inventing the same nonexistent package should be rare. It happened twice in 30 prompts.

That's what turns a glitch into a pattern. A random mistake is hard to exploit. A repeatable one is a target.

Real, but not apocalyptic.

Six fake suggestions across 30 prompts is not a flood. Most of what these tools recommended was real, and my sample is small. But an attack like this only needs one hit:

The two names that appeared in more than one tool are the ones I'd worry about, because repetition is what makes a hallucination worth squatting on. And the two suspicious-but-real packages show the second layer: even a successful lookup doesn't tell you who is behind the package.

   npm view <package> time.created maintainers

   curl -s https://pypi.org/pypi/<package>/json | head -c 600

A moment from my own test: one of the fake names looked so real that I didn't doubt it for a second. Nothing about it felt off. The registry lookup was the only thing that caught it. My instincts didn't.

My process is the checklist above, and it only exists because one fake name in my test looked so real that my own instincts didn't flag it. The lookup did.

What's yours? How does your team check AI-suggested dependencies before they get installed: a process, a tool, or just trust?

Drop it in the comments. I'll collect the best answers into a follow-up.

── more in #ai-tools 4 stories · sorted by recency
── more on @claude 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/i-tested-3-ai-coding…] indexed:0 read:3min 2026-10-06 · —