New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
Blog post from Socket
A research preprint by Aleksandr Churilov, posted on arXiv and not yet peer-reviewed, examines nearly 200,000 code-generation responses from five frontier large language models, revealing a persistent issue of "package hallucination" where models invent non-existent package names on PyPI or npm. The study found hallucination rates ranging from 4.62% to 6.10%, with 127 package names initially identified as common across the models, of which 53 were still available for registration, posing potential security risks through a technique called slopsquatting. While the research highlights the threat of malicious use of these names, it found no evidence of such registrations, pointing out that shared public training data and ecosystem conventions might lead models to generate the same incorrect package references. The study's methodology included testing responses to approximately 40,000 prompts, with results showing Python package hallucinations were more frequent than those in JavaScript, reversing earlier findings. However, it noted limitations in registry checks and extraction methods, especially in identifying valid framework imports, suggesting that AI-generated dependencies should be treated cautiously and verified thoroughly before use in projects.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.