AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
AI models frequently hallucinate package names that do not exist in public registries, creating opportunities for supply-chain attacks known as slopsquatting. A researcher examined 139 names that five recent AI models consistently invented and checked their status on PyPI and npm as of 22 September. Seven names were already registered, with one previously hosting malicious code.
The attack works when developers copy installation commands such as pip install or npm install directly from AI responses without verification. If the name is available, an attacker can register it and include arbitrary code that runs with the developer’s privileges, exposing keys, tokens, and environment variables. This mirrors typosquatting but relies on consistent model errors rather than human typos.
Among the registered names, metro-evaluator on npm contained malicious code published in four versions on 7 December 2025 and removed five days later. npm replaced it with a security-hold placeholder. The package had been suggested by the tested models a total of ten times. Another name, css-color-stop, was registered after the list became public and contains only a 53-byte package.json file with no executable code.
Four other occupied names belong to legitimate but unrelated projects: odf, lusid, usr, and ssh-keys. The odf package on PyPI receives nearly 5,000 downloads per month and is unrelated to the OpenDocument library developers likely intended. The real weaviate client is published under weaviate-client, while the brand owner maintains an empty placeholder under the hallucinated name.
Earlier research cited in the report found hallucination rates of 19.7% across 16 models and 576,000 code snippets. Commercial models averaged 5.2% while open-source models reached 21.7%. A separate study of five newer models reported rates between 4.62% and 6.10%. One documented case showed the empty huggingface-cli package on PyPI accumulating over 30,000 downloads after an incorrect command appeared in an Alibaba repository.
AI coding agents increase the risk because they can execute installation commands autonomously. In one campaign, the name react-codeshift appeared in 47 generated files and spread to more than 237 repositories. Researchers demonstrated prompt-injection techniques that tricked agents into requesting attacker-controlled package names with success rates up to 100% on tools including Cursor, Windsurf, and GitHub Copilot.
Registry operators already block many hallucinated names through normalization and prohibition lists, leaving approximately 53 names still available for registration. The study emphasizes that developers and team leads should require human approval before AI agents install dependencies and should inspect package metadata with commands such as npm view or PyPI JSON endpoints before installation.
Related articles
Sapper Revives Minefield to Deliver Accurate SBOM-Based Vulnerability Impact Reports for Cyber Resilience Act Compliance
Developer Perruer has forked the archived BitBom project Minefield into a new open-source tool called Sapper, fixing critical bugs in dependency graph construction and vulnerability matching. The original Minefield used roaring bitmaps and Tarjan's algorithm to build transitive dependency caches from SBOMs in O(n + m) time, but it incorrectly interpreted SPDX edge directions from protobom 0.6, creating false cycles and massively inflating dependent package counts. Additional fixes addressed SQLite memory database pooling issues, OSV range sorting errors with Go pseudo-versions and ECOSYSTEM ecosystems, and slow OSV ingestion by adding a package name index. Sapper now produces prioritized reports using CISA KEV and EPSS scores, showing exact shortest paths from vulnerable packages to root products while respecting OpenVEX statements. The tool maintains full air-gapped operation and supports CycloneDX 1.3–1.7 and SPDX 2.x formats. These improvements directly help organizations meet the 24-hour notification requirements under the EU Cyber Resilience Act for actively exploited vulnerabilities.
Fake Terraform Providers on HashiCorp Registry Distribute Go Malware to Developers
Cybersecurity researchers have identified Go-based malware distributed through two fake Terraform providers and two Go modules hosted on the official HashiCorp registry. The providers gocommunity-io/dockerd and kreuzwenker/docker, along with modules gocommunity.io/orderedbtree and gogets.dev/btreex, impersonate legitimate projects and represent the first documented case of malicious code being delivered via the HashiCorp registry. Attackers approach developers on LinkedIn, Facebook, and job forums using fake Web3 company profiles, then supply seemingly harmless repositories whose malicious behavior is triggered through npm or PyPI dependencies. Once executed, the malware collects hardware attributes, operating system data, hostname, and node availability before sending the information to attacker infrastructure. Command and control relies on a Slack channel polled every ten seconds and encrypted commands read from Sepolia testnet Ethereum smart contracts every three seconds, with each infected client using ephemeral key pairs for targeted delivery. The code matches the Graphalgo campaign previously documented by ReversingLabs and attributed to North Korean actors.
Challenges in Building Accurate SBOMs for C and C++ Projects Highlighted by CodeScoring Analysis
C and C++ ecosystems lack centralized package manifests, making SBOM generation far more complex than in Python, Java, or JavaScript. Libraries may arrive through system package managers like apt or dnf, build tools such as Conan and vcpkg, or direct source inclusion, with no single record of all components. CodeScoring’s Johnny agent uses eBPF to observe linker commands during builds and cross-references results with dpkg, RPM, and pkg-config metadata. The analysis distinguishes build-time SBOMs, which capture static libraries and compilation commands, from runtime SBOMs that reflect dynamic dependencies at execution. When version data cannot be verified, components are explicitly marked unresolved rather than guessed. The approach also addresses header-only libraries and patched artifacts that defeat simple hash matching.
CrowdSec Confirms Theft of Source Code from Roughly 300 GitHub Repositories via TanStack Supply Chain Attack
French cybersecurity firm CrowdSec has confirmed that attackers stole source code from approximately 300 GitHub repositories, including around 170 private ones. The breach occurred in May 2026 through a compromised TanStack component that exfiltrated an API key with read access to the private codebase. The stolen material included code for the company's SaaS console, AWS procedures, connectors, and automation tools, while the remaining repositories contained already-public open source code. No customer data, passwords, organization details, tokens, or other secrets were included in the leak, and all potentially affected credentials were immediately rotated. CrowdSec stated that the code is tightly integrated with internal systems and has largely changed over the past four months, reducing its usefulness outside the company's environment. The SaaS service code undergoes regular audits, and the company sees no immediate threat from the exposure while the investigation continues.