Forget typosquatting; slopsqua... Note
VentureBeat

Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools

Slopsquatting is a new supply chain attack leveraging AI hallucinations to inject malware into software development. Attackers exploit Large Language Models' (LLMs) tendency to invent plausible-sounding but non-existent software package names. These made-up names are then registered by cybercriminals and populated with malicious code. Developers using AI coding assistants unknowingly incorporate these fake packages into their projects. Unlike traditional typosquatting, where misspelled popular names are used, slopsquatting relies on AI-generated fictitious names. This makes existing security measures ineffective. Hallucinations in LLMs are frequent, with some models hallucinating packages over 50% of the time. This persistence allows attackers to reliably register names that LLMs will recommend. Open-source LLMs are significantly more prone to this issue than proprietary ones. The increasing reliance on AI for coding, known as "vibe coding," amplifies this threat surface. Developers must diligently verify all recommended package names against official repositories. Implementing automated checks and staying informed about slopsquatting campaigns are vital for defense.
CdXz5zHNQW_fJjvFzcygI.png