Analysis · curated 13 Aug 2026

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

Coverage timeline

13 Aug 2026bleepingcomputer.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Slopsquatting turns AI-assistant package hallucinations into a machine-speed software supply-chain attack vector, letting adversaries pre-register hallucinated names and infiltrate automated developer builds before any human review.

A sponsored ActiveState article explains "slopsquatting," where LLM coding assistants hallucinate non-existent package names that attackers then register on PyPI or npm with malicious payloads, feeding compromised dependencies into CI/CD pipelines. It cites a USENIX Security study across 16 code-generation models and 500,000+ samples showing measurable rates of hallucinated and CVE-laden package suggestions, and claims a 2026 example (react-codeshift) spread to 230+ repositories.