# Slopsquatting: The Supply Chain Attack Your AI Coding Assistant Might Be Setting Up For You

> Source: <https://dev.to/uo_buddies_df655d00f08b61/slopsquatting-the-supply-chain-attack-your-ai-coding-assistant-might-be-setting-up-for-you-6em>
> Published: 2026-10-07 21:05:08+00:00

You ask your AI assistant for a quick script. It writes clean code, imports a package you've never heard of, and you run `pip install`. It installs without errors.

But what if that package didn't exist until last week, and the person who created it wants your API keys?

That's **slopsquatting**, and it's one of the more interesting security problems of the AI-assisted coding era.

LLMs sometimes "hallucinate" package names. They recommend a library that sounds perfectly plausible but doesn't exist. Slopsquatting is when an attacker notices these recurring fake names and registers them on a public registry like PyPI or npm, loaded with malicious code.

It's a cousin of **typosquatting**, where attackers register `reqeusts` hoping you'll mistype `requests`. The difference is that here nobody mistypes anything. The model invents the name, and you trust it.

Research on package hallucination in code-generating models (a 2025 study analyzing hundreds of thousands of generated code samples) found three important things:

Exact rates vary by model, language, and prompt, so treat any single percentage as a snapshot rather than a constant. The pattern is what matters.

Steps 4 and 5 are the dangerous ones. Install-time scripts can run arbitrary code before you've even read a line of the package.

Agentic workflows changed the risk profile. When you copy a snippet, a human at least glances at the import. Coding agents that can run shell commands may install dependencies automatically to "make the tests pass." Fewer human checkpoints means fewer chances to catch a bad name.

Parallel agents, CI-triggered agents, and "vibe coding" sessions where nobody reads the dependency list all widen the window.

You don't need to stop using AI tools. You need a few habits.

Before adding an unfamiliar dependency, check:

A 30-second look catches most of this.

Use lockfiles (`package-lock.json`, `poetry.lock`, `requirements.txt` with hashes). Hash-pinning in particular means an unexpected package can't silently slip in later.

```
pip install --require-hashes -r requirements.txt
```

For teams, route installs through an internal proxy (Artifactory, Nexus, or similar) that only permits approved packages. A hallucinated name simply fails to resolve.

```
npm config set ignore-scripts true
```

This won't stop malicious code at import time, but it removes a major execution path during install.

Run coding agents in containers or dev environments with no access to production secrets, SSH keys, or cloud credentials. Assume any dependency an agent installs is untrusted until reviewed.

Tools like `pip-audit`, `npm audit`, Socket, Snyk, and OSV-Scanner flag known-bad and suspicious packages. Make new-dependency diffs a required review item in pull requests.

Ask your assistant to prefer well-known standard-library or already-installed dependencies, and to tell you whenever it introduces a new one. It's not foolproof, but it surfaces additions you'd otherwise miss.

Slopsquatting isn't really an AI problem. It's an old trust problem, "I'll run whatever the internet tells me to install," with a new and very persuasive source of suggestions.

AI assistants are great at producing plausible output. Plausible and correct aren't the same thing, and the gap between them is exactly where attackers operate.

Use the tools. Just treat every new dependency like a stranger asking for the keys to your house.
