{"slug": "i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they", "title": "I Tested 3 AI Coding Tools for Slopsquatting. Here's How Many Fake Packages They Invented.", "summary": "A developer tested three AI coding assistants across 30 prompts and found they suggested six nonexistent package names, with two fake names appearing in more than one tool — a pattern the author says makes \"slopsquatting\" attacks predictable and targetable. The experiment also surfaced two real but very new, low-download packages, which the author notes can be just as risky as fabricated ones. The developer withheld the fake names to avoid handing attackers a shopping list, and published registry-lookup commands (npm view, PyPI JSON API) as a verification step.", "body_md": "It's 2 a.m. and I'm not hacking anything. I'm watching a list.\n\nThe list is made of package names that don't exist, recommended to thousands of developers by an assistant that sounds very sure of itself. All I have to do is register one of them and wait.\n\nI don't need a zero-day. I don't need to phish anyone. The developer will install my code for me, because their AI told them to.\n\nSo I ran the experiment from the defender's side. **How long would that list be?**\n\nAn AI coding tool suggests a package that doesn't exist. An attacker registers that exact name on npm or PyPI and puts something nasty inside. A developer copies the install command, and it works.\n\nThe term was coined by Seth Larson of the Python Software Foundation. It differs from typosquatting in one important way: **no human makes a typo. The model makes the mistake, confidently.**\n\nMost posts on this topic are explainers or quote someone else's statistic. One recent preprint (not yet peer-reviewed) [reported that five different LLMs invented the same 127 package names](https://www.infoworld.com/article/4200884). If hallucinations repeat across models, they're predictable, and predictable means targetable.\n\nIt also means you can test it yourself. So I did.\n\n| Tool | Fake packages found | \n|---|---|\n| Claude (Haiku 4.5) | 2 | \n| GitHub Copilot (auto) | 1 | \n| ChatGPT / Codex | 3 | \n\nAcross 30 prompts, the three tools made **6 fake package suggestions** that don't exist on npm (counted per tool).\n\n**Overlap:** **2 of those fake names showed up in more than one tool.**\n\n**Suspicious but real:** **2 packages** existed but were very new or had almost no downloads. \"It exists\" is not the same as \"it's safe.\" A package someone registered last week can be exactly what an attacker wants you to find.\n\nI'm deliberately not publishing the fake names. A list of unregistered, AI-popular package names is a shopping list for attackers.\n\nTwo fake names appeared in more than one tool.\n\nI expected noise. If each tool were simply guessing, two *different* products independently inventing the *same* nonexistent package should be rare. It happened twice in 30 prompts.\n\nThat's what turns a glitch into a pattern. A random mistake is hard to exploit. A repeatable one is a target.\n\nReal, but not apocalyptic.\n\nSix fake suggestions across 30 prompts is not a flood. Most of what these tools recommended was real, and my sample is small. But an attack like this only needs **one** hit:\n\nThe two names that appeared in more than one tool are the ones I'd worry about, because repetition is what makes a hallucination worth squatting on. And the two suspicious-but-real packages show the second layer: even a successful lookup doesn't tell you who is behind the package.\n\n```\n   # npm: creation date and maintainers\n   npm view <package> time.created maintainers\n\n   # PyPI: metadata and release history\n   curl -s https://pypi.org/pypi/<package>/json | head -c 600\n```\n\n**A moment from my own test:** one of the fake names looked so real that I didn't doubt it for a second. Nothing about it felt off. The registry lookup was the only thing that caught it. My instincts didn't.\n\nMy process is the checklist above, and it only exists because one fake name in my test looked so real that my own instincts didn't flag it. The lookup did.\n\n**What's yours? How does your team check AI-suggested dependencies before they get installed: a process, a tool, or just trust?**\n\nDrop it in the comments. I'll collect the best answers into a follow-up.", "url": "https://wpnews.pro/news/i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they", "canonical_source": "https://dev.to/harsh2644/i-tested-3-ai-coding-tools-for-slopsquatting-heres-how-many-fake-packages-they-invented-76b", "published_at": "2026-10-06 20:58:15+00:00", "updated_at": "2026-10-06 21:18:21.703520+00:00", "lang": "en", "topics": ["ai-tools", "ai-safety", "ai-agents", "developer-tools"], "entities": ["Claude", "GitHub Copilot", "ChatGPT", "Codex", "npm", "PyPI", "Seth Larson", "Python Software Foundation"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they", "markdown": "https://wpnews.pro/news/i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they.md", "text": "https://wpnews.pro/news/i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they.txt", "jsonld": "https://wpnews.pro/news/i-tested-3-ai-coding-tools-for-slopsquatting-here-s-how-many-fake-packages-they.jsonld"}}