Analysis · curated 13 Aug 2026
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
First reported · updated · 2 reports bleepingcomputer.com
Coverage timeline
Why it matters
Slopsquatting turns AI coding assistants into a supply-chain attack vector, letting adversaries seed malicious packages that automated developer and CI/CD environments ingest at machine speed without human vetting.
A sponsored ActiveState article explains slopsquatting (AI package hallucination exploitation), where LLM coding assistants suggest non-existent package names that attackers then register on PyPI/npm with malicious payloads to be fetched by CI/CD pipelines. It cites a USENIX Security study across 16 code-generation models and 500,000+ samples, and a 2026 example where a hallucinated npm package name (react-codeshift) spread through forks to over 230 repositories.