Analysis
What is 'SlopSquatting'? - YouTube
Publication date not yet evaluated · Added · 2 reports youtube.com
Page published
Coverage timeline
Why it matters
Slopsquatting turns predictable AI hallucinations into a real software supply-chain vector, meaning developers who trust AI-suggested dependencies can be tricked into installing attacker-controlled malicious packages.
Tanya Janca (SheHacksPurple) explains 'slopsquatting,' a software supply-chain attack in which an AI coding assistant hallucinates a non-existent package name, and a malicious actor then registers that name and fills it with harmful code so developers unwittingly download it. The one-minute video defines the concept and warns developers against blindly trusting AI-generated package recommendations.