Threat · curated 20 Aug 2026

AI agent suggested installing a malware package. Engineer almost took its advice

Coverage timeline

20 Aug 2026theregister.com

Why it matters

Slopsquatting weaponizes AI coding assistants' tendency to hallucinate plausible package names, letting attackers seed supply-chain compromises that developers under deadline pressure may install without checking.

An engineer at Softjourn nearly installed a malware package after an AI agent recommended a legitimate-sounding but hallucinated package name — an attack pattern called 'slopsquatting,' where attackers register real malicious packages under names AI models are known to invent. The developer caught it by following company policy to verify download counts and review GitHub source before installing.