Pervasive LLM Hallucinations Expand Code Developer Attack Surface
ID: d48f7a17-1fef-596d-b7c6-c37cb7e202a2
STIX ID: report--d48f7a17-1fef-596d-b7c6-c37cb7e202a2
Feed Name: Dark Reading
Lasso Security research found that major LLMs (GPT-3.5, GPT-4, Gemini Pro, Coral/Cohere) often invent nonexistent package names when asked for coding libraries; attackers can exploit this by publishing malicious packages with those exact names—one such proof-of-concept upload of a hallucinated "huggingface-cli" package received more than 32,000 downloads. The study measured high hallucination and repetition rates (e.g., Gemini ~64.5% hallucination rate; repetitiveness up to ~24% for some models) and warns developers to verify package provenance, community activity, maintenance, and scan packages before adding them to development environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
