2025-04-27 10:09:44.AIbase.17.6k
Developer Alert! One-Fifth of AI-Recommended Packages are Fake: Slopsquatting Threat Emerges
Cybersecurity researchers warn of a new software supply chain attack called "Slopsquatting." This attack exploits the 'package hallucination' phenomenon – where generative AI (like LLMs) may suggest non-existent package names during code writing. Attackers can preemptively register these fictitious names and inject malicious code. Image Note: Image generated by AI, courtesy of Midjourney. Research reveals that AI-fabricated package names often exhibit a high degree of...