Research · curated 27 Jul 2026

The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort

Coverage timeline

discovered arxiv.org primary 22 Jul 2026socket.dev 7 Aug 2026infoworld.com

Why it matters

Slopsquatting on package names that multiple frontier LLMs hallucinate identically gives attackers a durable, cross-model supply-chain foothold, since a single malicious registration can poison code generated by any of the models.

A replication study by Aleksandr Churilov re-evaluated package-name hallucination across five 2026 frontier code LLMs (Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, DeepSeek V3.2), measuring hallucination rates of 4.62%-6.10% across ~199,845 Python/JavaScript prompts. The authors identified 127 package names all five models invent identically and, after coordinated disclosure with PyPI Security and Socket, found 53 (41 PyPI, 12 npm) remain registrable by an attacker, forming a model-agnostic slopsquatting supply-chain attack surface.