Attackers are exploiting AI-generated dependency hallucinations by registering malicious packages under names that coding assistants and autonomous agents invent, a technique known as slopsquatting or hallusquatting. The threat has progressed from a 2023 proof of concept around the nonexistent package huggingface-cli to broader evidence that AI tools repeatedly recommend packages that do not exist; a 2025 academic measurement found 19.7% of AI-suggested Python and JavaScript packages were nonexistent, with many hallucinated names recurring across prompts and models.
The risk escalated in 2026 as hallucinated package names began propagating through agentic development workflows and automated installs. Researchers reported the fake npm package name react-codeshift spreading across 237 repositories, while the malicious package unused-imports continued to be installed, showing how model output can become a software supply-chain infection path. A July 2026 HalluSquatting variant further combined hallucinated resources with prompt injection to drive AI coding agents toward remote code execution (RCE), expanding the attack surface from human typo-based dependency mistakes to model-generated and agent-executed compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In July 2026, researchers described 'HalluSquatting,' a technique that combines hallucinated resources with prompt injection to achieve remote code execution in AI coding agents. The report marked a further escalation from dependency confusion-style abuse to direct compromise of autonomous agent workflows.
Also in 2026, the malicious package 'unused-imports' was described as continuing to receive installs. This indicated ongoing real-world exploitation of hallucinated or misleading dependency names in package ecosystems.
In 2026, hallucinated package names were reported to have propagated through autonomous coding-agent workflows, including the fake npm package name 'react-codeshift' appearing across 237 repositories. The article presents this as an escalation from human-assisted misuse to agent-amplified spread.
In 2025, academic measurement found that 19.7% of Python and JavaScript packages recommended by AI models did not exist. The study also reported that many hallucinated package names were repeatable, increasing their usefulness to attackers who register them.
In 2023, a proof-of-concept showed that an attacker could register a malicious package under an AI-hallucinated dependency name, using the nonexistent package name 'huggingface-cli' as an example. This established slopsquatting as a software supply-chain risk tied to AI-generated coding suggestions.
An independent preprint found that five frontier code-generating LLMs hallucinated shared nonexistent PyPI and npm package names, and after review by PyPI Security and Socket, 53 of those names were still registrable as of April 2026. The study analyzed 199,845 model responses and highlighted ongoing software supply-chain risk from cross-model package hallucinations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
socket.dev
Open sourcexygeni.io
Open sourcemeetcyber.net
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.