Analysis

What is 'SlopSquatting'? - YouTube

Page published

Coverage timeline

23 Aug 2026youtube.comobserved 3 Sep 2026x.comobserved

Why it matters

Slopsquatting turns predictable AI hallucinations into a real software supply-chain vector, meaning developers who trust AI-suggested dependencies can be tricked into installing attacker-controlled malicious packages.

Tanya Janca (SheHacksPurple) explains 'slopsquatting,' a software supply-chain attack in which an AI coding assistant hallucinates a non-existent package name, and a malicious actor then registers that name and fills it with harmful code so developers unwittingly download it. The one-minute video defines the concept and warns developers against blindly trusting AI-generated package recommendations.