logo

AI Code Tools Widely Hallucinate Packages

ID: be403872-17f7-5c1d-93e6-7fe87f9d5198

STIX ID: report--be403872-17f7-5c1d-93e6-7fe87f9d5198

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-04-14

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Researchers analyzed 16 code-generating LLMs and found a widespread problem of "package hallucinations," where models invent non-existent npm/PyPI package names; these hallucinations occur frequently (open-source models ~21.7%, commercial ~5.2%) and are often repeated across runs. The study warns that attackers can exploit repeated hallucinated names by publishing malicious packages with those names (a supply-chain attack vector labeled "slopsquatting"), shows models sometimes self-identify hallucinations, and cites prior work demonstrating real-world downloads of an uploaded invented package.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.