One in Five AI-Suggested Packages Are Fake; Attackers Can Identify Them
| Source: Dev.to | Original article
AI coding assistants frequently suggest packages that don’t exist—roughly one in five recommendations—giving attackers a way to exploit the bogus dependencies.
A new study has revealed that roughly one‑in‑five package names generated by AI‑powered coding assistants are pure hallucinations. When developers ask an assistant for a library and receive a confident install command, the suggested package often does not exist at all. Researchers found that attackers are exploiting this flaw by pre‑emptively registering the bogus names on public registries such as PyPI, npm and crates.io, turning a harmless miss‑install into a supply‑chain foothold.
The phenomenon, dubbed “slopsquatting,” blends the classic typosquatting tactic with the systematic errors of large language models. Because the AI does not merely misspell a real package but invents a plausible‑looking name, the malicious registration can go unnoticed until the developer runs the install command. Once installed, the counterfeit package can deliver malware or exfiltrate code, extending the threat surface that we previously highlighted in our coverage of AI‑driven hacking attacks [2026‑09‑29].
The findings matter for anyone who relies on AI code suggestions, from hobbyists to enterprise teams. A failed install is an annoyance; a malicious payload, however, can compromise production systems, leak credentials, or provide a foothold for further intrusion. The study also notes that the hallucination rate varies between 19 % and 20 % across different assistants, underscoring a systemic issue rather than an isolated bug.
Watch for rapid responses from the open‑source ecosystem. Tools such as Phantom Guard are already emerging to flag non‑existent packages before they reach a developer’s environment. Registry operators may tighten name‑reservation policies, and AI vendors are expected to integrate real‑time verification into their suggestion pipelines. The next few weeks will likely see a mix of defensive tooling, policy updates and possibly new standards for AI‑generated dependency recommendations.
Sources
Back to AIPULSEN