logo

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

ID: b66fd183-512f-5237-9f6b-5c6fdd8c9c20

STIX ID: report--b66fd183-512f-5237-9f6b-5c6fdd8c9c20

Feed Name: Socket Blog

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Sarah Gooding

...
...

Independent research analyzed ~199,845 code-generation responses from five frontier LLMs and found package-hallucination rates of 4.62%–6.10%. The study identified 127 package names produced by all models; after reviews by PyPI Security and Socket, 53 of those names (41 PyPI, 12 npm) were still registrable, creating potential slopsquatting targets an attacker could register to distribute malware. The paper documents limitations (regex-extraction false positives, single-response sampling, changing registries) and recommends treating AI-suggested dependencies as unverified until package provenance and publisher history are confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.