Researchers and security vendors warned that slopsquatting has evolved into a practical software supply-chain threat as code-generating LLMs repeatedly recommend nonexistent package names that attackers can register and weaponize. An arXiv study, We Have a Package for You!, found that 19.7% of packages suggested by tested code-generation models did not exist, reinforcing earlier demonstrations that hallucinated names are often stable enough to be predicted and abused rather than being purely random errors.
The threat has expanded from misleading human developers to compromising AI coding agents and automated workflows. Reporting cited the spread of the hallucinated npm package react-codeshift across 237 repositories, continued downloads of a malicious package named unused-imports, and a newer HalluSquatting technique that combines hallucinated resources with prompt injection to steer AI-assisted development tools into fetching and executing attacker-controlled code.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In July 2026, researchers described "HalluSquatting," a technique that combines hallucinated resources with prompt injection to hijack AI coding agents into executing attacker-controlled code.
In 2026, the malicious package named "unused-imports" was still receiving downloads, showing that attackers were successfully weaponizing hallucinated package names.
In 2026, the hallucinated npm package name "react-codeshift" was found propagated across 237 repositories, indicating the threat had expanded from human developers to AI coding agents.
In 2025, a USENIX study reported that 19.7% of packages recommended by the tested code-generation models did not exist, providing quantitative evidence that slopsquatting had become a measurable threat.
In 2023, Bar Lanyado demonstrated the slopsquatting concept using the nonexistent package name "huggingface-cli," showing how hallucinated dependency names could create a software supply-chain risk.
An academic paper titled "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs" was published on arXiv, documenting package hallucination behavior in code-generating models.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.