Frontier LLMs hallucinate identical nonexistent package names
An independent study found that five leading LLMs generated the exact same nonexistent package names across 200,000 coding prompts. Socket and PyPI Security discovered 53 of these hallucinated packages available for registration, exposing developers who blindly copy AI-generated code to a novel 'slopsquatting' vulnerability.
This research exposes a critical intersection between AI hallucinations and supply chain security.
- –"Slopsquatting" introduces a new attack vector that targets AI-assisted developers rather than traditional typosquatting victims.
- –The fact that five different frontier models converge on the exact same hallucinated package names suggests a systemic issue, likely stemming from shared training data or architectural similarities.
- –This underscores the urgent need for developers to verify AI-generated dependencies and for package registries to proactively monitor and block hallucinated package names.
DISCOVERED
2h ago
2026-07-22
PUBLISHED
3h ago
2026-07-22
RELEVANCE
AUTHOR
SocketSecurity
