Ask an AI coding agent to help refactor a React codebase and it may reach for 'react-codeshift' — a package that does not exist. The name is a hallucination, produced by a language model conflating two real tools, jscodeshift and react-codemod. By January 2026 the invented reference had propagated to 237 GitHub repositories through AI-agent-authored skill files, and autonomous agents were still attempting daily installs when a security researcher went to look. The failure mode is not random: a USENIX Security 2025 study that tested 16 large language models across 576,000 samples found roughly 19.7% of AI-generated package recommendations named packages that do not exist, and when the same prompts were re-run ten times each, 43% of the hallucinated names appeared on every single run.
1 Answer
Expert: Charlie Eriksen, Security researcher, Aikido Security Charlie Eriksen, a security researcher at Aikido Security, coined the term 'slopsquatting' for the attack class this creates. Typosquatting needs a human to mistype a package name. Slopsquatting needs only an AI agent to keep hallucinating one — and an attacker who registers it first. Eriksen registered react-codeshift in January 2026 to take it off the table. The hallucinated reference had already spread to 237 GitHub repositories via AI-generated agent skill files, and daily download attempts from autonomous agents were recorded immediately after registration. 'This was a hallucination,' Eriksen said. 'It spread to 237 repositories. It generated real download attempts. The only reason it didn't become an attack vector is because I got there first.' The usual defence against a name-squatting attack — npm's collision detection for packages whose names resemble existing ones — does nothing here. A hallucinated name is a brand-new string with no existing package to collide with. What makes the failure exploitable is its repeatability. When researchers re-ran identical prompts ten times each, 43% of the hallucinated package names appeared on every run. An attacker needs only to run a few dozen prompts against a popular model, identify the names that keep recurring, and register them before anyone else does. And the agent does not hesitate. A human engineer pausing to check a package's download count, maintainer history or an unfamiliar name is the everyday behavioural defence against open-source supply-chain attacks. An AI coding agent resolving dependencies does none of that: it installs and moves on, which is exactly what it was built to do. The wider record points the same way. Phoenix Security's 2026 supply chain report found the first half of 2026 produced more than 2.6 times the campaign volume and 4.5 times the package compromise volume of all of 2025 combined. A separate campaign documented by ReversingLabs, PromptMink, went beyond imitating real package names — it wrote package documentation designed to look authoritative to a large language model rather than to a human reader — and researchers later found a legitimate hackathon project whose dependency history showed the malicious package had been added in a commit co-authored by an AI coding agent. For anyone running agents, the correction is procedural: verify package names against the registry before install, pin and lock dependencies, and treat agent-authored dependency additions as untrusted input. Verification is the one step the model will not do for you. Source: https://www.techtimes.com/articles/319457/20260701/ai-coding-agents-skip-package-verification-attackers-are-exploiting-it.htm
Your answer
Sign in to verify this AI response.
Don't trust us — or the AI. Ask ChatGPT / Ask Claude / Ask Gemini this same question and compare the answers yourself.
More from this topic
Amazon's retail website took four high-severity incidents in a single week, including a six-hour meltdown that locked shoppers out of checkout, account information and product pricing. Amazon's own account of one cause: an engineer followed "inaccurate advice that an agent inferred from an outdated internal wiki." Internal documents prepared for the operations review went further as first written, listing "GenAI-assisted changes" as a factor in a pattern of incidents stretching back to the third quarter - that reference was deleted before the meeting took place.
Three AI coding agents - Claude Code running Sonnet 4.6, OpenAI Codex on GPT 5.2 and Google Gemini on 2.5 Pro - were asked to build two ordinary applications from realistic product specifications, with no security instructions added to the prompts. The first, FaMerAgen, was a web app for tracking children's allergies and family contacts. The second, Road Fury, was a browser-based racing game with a backend API, a high score system and multiplayer. Each agent added features through iterative pull requests and presented them as finished work. Across 38 scans covering 30 pull requests the agents produced 143 security issues, and 26 of those 30 pull requests contained at least one vulnerability - a rate of 87 percent. Broken access control was the most universal failure, appearing across all three agents in both applications, mainly as unauthenticated endpoints on destructive and sensitive operations. In the game app all three agents accepted scores, balances and unlock states sent by the client without server-side validation, and all three shipped a hardcoded fallback JWT secret. Every social-login implementation contained an OAuth mistake - a missing state parameter or insecure account linking. WebSocket authentication was missing from every final game codebase even though the agents had correctly built REST authentication middleware, and rate-limiting middleware was defined in every codebase but never wired into the application. The code compiled and ran.
Confirmation dialog shown to a developer before an AI coding assistant writes a file: "Make this edit to `project_settings.json`?" In Wiz Research's GhostApproval proof of concept, `project_settings.json` inside a cloned repository is a symbolic link pointing outside the workspace - at `~/.ssh/authorized_keys` or `~/.zshrc`. The agent follows the link and writes attacker-controlled content to the real target, which can give the attacker persistent password-less SSH access and reach remote code execution on the developer's machine, while the approval box showed only the harmless in-project path. In several of the tools the agent's own reasoning had already identified the true target - Claude Code stated "this is a symbolic link to the Claude settings file", and in another test "I can see that `project_settings.json` is actually a zsh configuration file" - yet the prompt presented to the human concealed it. Amazon Q Developer went further and wrote to the filesystem before showing the user anything, offering only an "Undo" option after the write had already happened.