I Tested 3 AI Coding Tools for Slopsquatting. Here's How Many Fake Packages They Invented. A developer tested three AI coding assistants across 30 prompts and found they suggested six nonexistent package names, with two fake names appearing in more than one tool — a pattern the author says makes "slopsquatting" attacks predictable and targetable. The experiment also surfaced two real but very new, low-download packages, which the author notes can be just as risky as fabricated ones. The developer withheld the fake names to avoid handing attackers a shopping list, and published registry-lookup commands (npm view, PyPI JSON API) as a verification step. It's 2 a.m. and I'm not hacking anything. I'm watching a list. The list is made of package names that don't exist, recommended to thousands of developers by an assistant that sounds very sure of itself. All I have to do is register one of them and wait. I don't need a zero-day. I don't need to phish anyone. The developer will install my code for me, because their AI told them to. So I ran the experiment from the defender's side. How long would that list be? An AI coding tool suggests a package that doesn't exist. An attacker registers that exact name on npm or PyPI and puts something nasty inside. A developer copies the install command, and it works. The term was coined by Seth Larson of the Python Software Foundation. It differs from typosquatting in one important way: no human makes a typo. The model makes the mistake, confidently. Most posts on this topic are explainers or quote someone else's statistic. One recent preprint not yet peer-reviewed reported that five different LLMs invented the same 127 package names https://www.infoworld.com/article/4200884 . If hallucinations repeat across models, they're predictable, and predictable means targetable. It also means you can test it yourself. So I did. | Tool | Fake packages found | |---|---| | Claude Haiku 4.5 | 2 | | GitHub Copilot auto | 1 | | ChatGPT / Codex | 3 | Across 30 prompts, the three tools made 6 fake package suggestions that don't exist on npm counted per tool . Overlap: 2 of those fake names showed up in more than one tool. Suspicious but real: 2 packages existed but were very new or had almost no downloads. "It exists" is not the same as "it's safe." A package someone registered last week can be exactly what an attacker wants you to find. I'm deliberately not publishing the fake names. A list of unregistered, AI-popular package names is a shopping list for attackers. Two fake names appeared in more than one tool. I expected noise. If each tool were simply guessing, two different products independently inventing the same nonexistent package should be rare. It happened twice in 30 prompts. That's what turns a glitch into a pattern. A random mistake is hard to exploit. A repeatable one is a target. Real, but not apocalyptic. Six fake suggestions across 30 prompts is not a flood. Most of what these tools recommended was real, and my sample is small. But an attack like this only needs one hit: The two names that appeared in more than one tool are the ones I'd worry about, because repetition is what makes a hallucination worth squatting on. And the two suspicious-but-real packages show the second layer: even a successful lookup doesn't tell you who is behind the package. npm: creation date and maintainers npm view