logo

Slopsquatting: AI's Contribution to Supply Chain Attacks

ID: bdcb44d9-33a9-5328-90e6-602f3c3dd306

STIX ID: report--bdcb44d9-33a9-5328-90e6-602f3c3dd306

Feed Name: HackerOne Blog

Threat Score
65/100

Date Published: 2025-07-16

Date Updated: 2026-06-21

...
...

Slopsquatting is an emerging software supply-chain vulnerability in which AI code-generation tools hallucinate nonexistent package names; adversaries can register those fabricated names and distribute malicious packages. The report reviews research showing significant hallucination rates (commercial models ~5.2%, open-source ~21.7%), notes the large scale of dependency use and past package hijacks, and recommends mitigations such as proxying package requests, providing explicit package lists, instructing models to verify packages, and carefully fine-tuning models.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.