Tool · curated 30 Sep 2026
sloppy-joe — Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.
First reported kitploit.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
sloppy-joe addresses slopsquatting, an AI-specific supply-chain risk where LLM-generated code recommends hallucinated package names that adversaries can pre-register, giving defenders a way to detect and block malicious or non-existent dependencies before they enter builds.
sloppy-joe is an open-source defensive tool (brennhill/sloppy-joe) that shields software projects against supply-chain, slopsquatting, and typosquatting attacks originating from dependencies and code. Slopsquatting specifically targets the AI-driven threat of LLMs hallucinating non-existent package names during code generation, which attackers can register to poison the supply chain; the project documents support across ecosystems (Python, JavaScript, Rust, Go, Ruby, PHP, JVM, .NET).