Slopsquatting: When AI Agents Hallucinate Malicious Packages
Blog post from Endor Labs
Slopsquatting is a growing threat in software supply chains, exploiting AI coding agents' tendency to hallucinate package names that do not exist. When these AI-generated names are suggested as dependencies, attackers can pre-register them with malicious code, leading to the unintentional installation of malware before developers can intervene. Unlike typosquatting, which targets human errors, slopsquatting leverages AI model errors by creating plausible but nonexistent package names, making traditional defenses like spell-check ineffective. The threat is exacerbated by agentic IDEs that auto-install dependencies, bypassing human review. To safeguard against slopsquatting, developers should verify package provenance, utilize dependency firewalls, enforce sandbox testing for AI-generated installs, and ensure human approval for new dependencies suggested by AI assistants. As AI adoption increases, it is crucial to audit its use and implement layered security measures to prevent such vulnerabilities from compromising codebases.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 11 | 1,487 | 422 | 149 | -31% |
| AI Agents | 2 | 5,827 | 1,275 | 245 | -5% |
| LLM | 1 | 6,942 | 1,215 | 234 | +11% |
| MCP | 1 | 7,621 | 787 | 203 | -1% |
| Real-time | 1 | 5,522 | 1,291 | 230 | -4% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.