Hallucinated Packages: How AI Invents Dependencies Attackers Exploit
Blog post from Endor Labs
AI coding tools can suggest hallucinated packages, plausible but nonexistent software dependencies that may enable “slopsquatting,” in which attackers register those names and distribute malware when developers install them. A 2025 study cited in the text found that 19.7% of more than 2.23 million AI-generated package references were hallucinations, with repeated fake names creating stable targets for attackers, while related research reported that many AI-recommended dependencies contain known vulnerabilities. Unlike typosquatting or dependency confusion, slopsquatting exploits AI-generated names rather than human spelling errors or registry-resolution behavior, so detection should focus on package provenance and malicious behavior. As AI-assisted development becomes widespread, the text argues that organizations should treat AI-generated code and dependencies as untrusted input by verifying packages before installation, reviewing imports and pull requests, detecting malicious packages at installation time, pinning versions, and prioritizing vulnerabilities based on whether they are actually reachable in deployed applications.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 5 | 341 | 115 | 55 | -77% |
| AI Agents | 1 | 931 | 231 | 103 | -84% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.