Analysis · curated 23 Aug 2026

Dependency Confusion, Typosquatting, and Slopsquatting: The New Danger of Installing Libraries

Coverage timeline

23 Aug 2026youtube.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Slopsquatting weaponizes LLM package-name hallucinations against developers and AI coding agents, expanding the software supply-chain attack surface in a way defenders vetting dependencies must account for.

A Spanish-language YouTube explainer video covers software supply-chain attacks — dependency confusion, typosquatting, and slopsquatting — with the AI angle that coding assistants can hallucinate nonexistent library names that attackers then register to exploit future model recommendations. The video also discusses lockfiles, hashes, SBOM, SLSA, and best practices for vetting dependencies, and notes it was itself produced with AI assistance for informational purposes.