{"slug": "slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting", "title": "Slopsquatting: The Supply Chain Attack Your AI Coding Assistant Might Be Setting Up For You", "summary": "A developer-focused security writeup warns that AI coding assistants can hallucinate non-existent package names, a vulnerability dubbed \"slopsquatting\" that attackers exploit by registering those fake names on registries like PyPI and npm with malicious code. The piece cites a 2025 study of hundreds of thousands of generated code samples on package hallucination and recommends mitigations including lockfiles with hash-pinning, blocking install scripts, internal package proxies, sandboxed agents, and dependency auditing tools.", "body_md": "You ask your AI assistant for a quick script. It writes clean code, imports a package you've never heard of, and you run `pip install`. It installs without errors.\n\nBut what if that package didn't exist until last week, and the person who created it wants your API keys?\n\nThat's **slopsquatting**, and it's one of the more interesting security problems of the AI-assisted coding era.\n\nLLMs sometimes \"hallucinate\" package names. They recommend a library that sounds perfectly plausible but doesn't exist. Slopsquatting is when an attacker notices these recurring fake names and registers them on a public registry like PyPI or npm, loaded with malicious code.\n\nIt's a cousin of **typosquatting**, where attackers register `reqeusts` hoping you'll mistype `requests`. The difference is that here nobody mistypes anything. The model invents the name, and you trust it.\n\nResearch on package hallucination in code-generating models (a 2025 study analyzing hundreds of thousands of generated code samples) found three important things:\n\nExact rates vary by model, language, and prompt, so treat any single percentage as a snapshot rather than a constant. The pattern is what matters.\n\nSteps 4 and 5 are the dangerous ones. Install-time scripts can run arbitrary code before you've even read a line of the package.\n\nAgentic workflows changed the risk profile. When you copy a snippet, a human at least glances at the import. Coding agents that can run shell commands may install dependencies automatically to \"make the tests pass.\" Fewer human checkpoints means fewer chances to catch a bad name.\n\nParallel agents, CI-triggered agents, and \"vibe coding\" sessions where nobody reads the dependency list all widen the window.\n\nYou don't need to stop using AI tools. You need a few habits.\n\nBefore adding an unfamiliar dependency, check:\n\nA 30-second look catches most of this.\n\nUse lockfiles (`package-lock.json`, `poetry.lock`, `requirements.txt` with hashes). Hash-pinning in particular means an unexpected package can't silently slip in later.\n\n```\npip install --require-hashes -r requirements.txt\n```\n\nFor teams, route installs through an internal proxy (Artifactory, Nexus, or similar) that only permits approved packages. A hallucinated name simply fails to resolve.\n\n```\nnpm config set ignore-scripts true\n```\n\nThis won't stop malicious code at import time, but it removes a major execution path during install.\n\nRun coding agents in containers or dev environments with no access to production secrets, SSH keys, or cloud credentials. Assume any dependency an agent installs is untrusted until reviewed.\n\nTools like `pip-audit`, `npm audit`, Socket, Snyk, and OSV-Scanner flag known-bad and suspicious packages. Make new-dependency diffs a required review item in pull requests.\n\nAsk your assistant to prefer well-known standard-library or already-installed dependencies, and to tell you whenever it introduces a new one. It's not foolproof, but it surfaces additions you'd otherwise miss.\n\nSlopsquatting isn't really an AI problem. It's an old trust problem, \"I'll run whatever the internet tells me to install,\" with a new and very persuasive source of suggestions.\n\nAI assistants are great at producing plausible output. Plausible and correct aren't the same thing, and the gap between them is exactly where attackers operate.\n\nUse the tools. Just treat every new dependency like a stranger asking for the keys to your house.", "url": "https://wpnews.pro/news/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting", "canonical_source": "https://dev.to/uo_buddies_df655d00f08b61/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting-up-for-you-6em", "published_at": "2026-10-07 21:05:08+00:00", "updated_at": "2026-10-07 21:17:10.207342+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-tools", "developer-tools"], "entities": ["PyPI", "npm", "pip-audit", "npm audit", "Socket", "Snyk", "OSV-Scanner", "Artifactory"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting", "markdown": "https://wpnews.pro/news/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting.md", "text": "https://wpnews.pro/news/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting.txt", "jsonld": "https://wpnews.pro/news/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting.jsonld"}}