Analysis · curated 13 Aug 2026
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
First reported bleepingcomputer.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Slopsquatting turns AI-assistant package hallucinations into a machine-speed software supply-chain attack vector, letting adversaries pre-register hallucinated names and infiltrate automated developer builds before any human review.
A sponsored ActiveState article explains "slopsquatting," where LLM coding assistants hallucinate non-existent package names that attackers then register on PyPI or npm with malicious payloads, feeding compromised dependencies into CI/CD pipelines. It cites a USENIX Security study across 16 code-generation models and 500,000+ samples showing measurable rates of hallucinated and CVE-laden package suggestions, and claims a 2026 example (react-codeshift) spread to 230+ repositories.