Analysis · curated 17 Aug 2026
AI Supply Chain Integrity – Max Hemingway
First reported · updated · 2 reports medium.com
Coverage timeline
Why it matters
AI-driven supply chain risks like slopsquatting turn LLM coding assistants into a new attack surface, letting adversaries pre-register hallucinated package names to compromise downstream builds, so defenders must extend provenance, SBOM/AI-BOM, and verification controls to AI-generated dependencies.
"AI Supply Chain Integrity" by Max Hemingway is an analysis of how AI is reshaping software supply chain security, synthesizing threats such as slopsquatting and LLM package hallucinations (where code-generating models invent non-existent dependency names that attackers can register), training-data poisoning, and the shift from SBOMs to AI-BOMs and model provenance. The piece draws on research including the USENIX study finding 5.2% (commercial) to 21.7% (open-source) hallucinated package rates across 576,000 code samples, alongside CISA AI-SBOM guidance and open-source ecosystem defense efforts.