Research · curated 27 Jul 2026

The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort

Coverage timeline

discovered arxiv.org primary 22 Jul 2026socket.dev

Single-source research — first reported, latest, and curated coincide.

Why it matters

Slopsquatting lets attackers register malicious packages under names that multiple LLMs consistently hallucinate, so developers relying on AI coding assistants can be steered into installing attacker-controlled dependencies via the software supply chain.

A replication study by Aleksandr Churilov re-evaluated LLM package hallucination rates across five 2026 frontier code-generating models (Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, DeepSeek V3.2), measuring hallucination rates between 4.62% and 6.10% across 199,845 Python and JavaScript prompts. The study identified 127 package names invented identically by all five models, of which 53 (41 PyPI, 12 npm) remained registrable by an attacker after coordinated disclosure to PyPI Security and Socket, forming a model-agnostic slopsquatting supply-chain attack surface.