Analysis
Dependency Confusion, Typosquatting, and Slopsquatting: The New Danger of Installing Libraries
Publication date not yet evaluated · Added youtube.com
Page published
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Slopsquatting weaponizes LLM package-name hallucinations against developers and AI coding agents, expanding the software supply-chain attack surface in a way defenders vetting dependencies must account for.
A Spanish-language YouTube explainer video covers software supply-chain attacks — dependency confusion, typosquatting, and slopsquatting — with the AI angle that coding assistants can hallucinate nonexistent library names that attackers then register to exploit future model recommendations. The video also discusses lockfiles, hashes, SBOM, SLSA, and best practices for vetting dependencies, and notes it was itself produced with AI assistance for informational purposes.