Threat · curated 20 Aug 2026
AI agent suggested installing a malware package. Engineer almost took its advice
First reported theregister.com
Coverage timeline
Why it matters
Slopsquatting weaponizes AI coding assistants' tendency to hallucinate plausible package names, letting attackers seed supply-chain compromises that developers under deadline pressure may install without checking.
An engineer at Softjourn nearly installed a malware package after an AI agent recommended a legitimate-sounding but hallucinated package name — an attack pattern called 'slopsquatting,' where attackers register real malicious packages under names AI models are known to invent. The developer caught it by following company policy to verify download counts and review GitHub source before installing.