# I Tested 3 AI Coding Tools for Slopsquatting. Here's How Many Fake Packages They Invented.

> Source: <https://dev.to/harsh2644/i-tested-3-ai-coding-tools-for-slopsquatting-heres-how-many-fake-packages-they-invented-76b>
> Published: 2026-10-06 20:58:15+00:00

It's 2 a.m. and I'm not hacking anything. I'm watching a list.

The list is made of package names that don't exist, recommended to thousands of developers by an assistant that sounds very sure of itself. All I have to do is register one of them and wait.

I don't need a zero-day. I don't need to phish anyone. The developer will install my code for me, because their AI told them to.

So I ran the experiment from the defender's side. **How long would that list be?**

An AI coding tool suggests a package that doesn't exist. An attacker registers that exact name on npm or PyPI and puts something nasty inside. A developer copies the install command, and it works.

The term was coined by Seth Larson of the Python Software Foundation. It differs from typosquatting in one important way: **no human makes a typo. The model makes the mistake, confidently.**

Most posts on this topic are explainers or quote someone else's statistic. One recent preprint (not yet peer-reviewed) [reported that five different LLMs invented the same 127 package names](https://www.infoworld.com/article/4200884). If hallucinations repeat across models, they're predictable, and predictable means targetable.

It also means you can test it yourself. So I did.

| Tool | Fake packages found | 
|---|---|
| Claude (Haiku 4.5) | 2 | 
| GitHub Copilot (auto) | 1 | 
| ChatGPT / Codex | 3 | 

Across 30 prompts, the three tools made **6 fake package suggestions** that don't exist on npm (counted per tool).

**Overlap:** **2 of those fake names showed up in more than one tool.**

**Suspicious but real:** **2 packages** existed but were very new or had almost no downloads. "It exists" is not the same as "it's safe." A package someone registered last week can be exactly what an attacker wants you to find.

I'm deliberately not publishing the fake names. A list of unregistered, AI-popular package names is a shopping list for attackers.

Two fake names appeared in more than one tool.

I expected noise. If each tool were simply guessing, two *different* products independently inventing the *same* nonexistent package should be rare. It happened twice in 30 prompts.

That's what turns a glitch into a pattern. A random mistake is hard to exploit. A repeatable one is a target.

Real, but not apocalyptic.

Six fake suggestions across 30 prompts is not a flood. Most of what these tools recommended was real, and my sample is small. But an attack like this only needs **one** hit:

The two names that appeared in more than one tool are the ones I'd worry about, because repetition is what makes a hallucination worth squatting on. And the two suspicious-but-real packages show the second layer: even a successful lookup doesn't tell you who is behind the package.

```
   # npm: creation date and maintainers
   npm view <package> time.created maintainers

   # PyPI: metadata and release history
   curl -s https://pypi.org/pypi/<package>/json | head -c 600
```

**A moment from my own test:** one of the fake names looked so real that I didn't doubt it for a second. Nothing about it felt off. The registry lookup was the only thing that caught it. My instincts didn't.

My process is the checklist above, and it only exists because one fake name in my test looked so real that my own instincts didn't flag it. The lookup did.

**What's yours? How does your team check AI-suggested dependencies before they get installed: a process, a tool, or just trust?**

Drop it in the comments. I'll collect the best answers into a follow-up.
