Mitigating the risks of package hallucination and ‘slopsquatting’

In 2024, cybersecurity experts started to warn of a new threat to the software supply chain. Named ‘slopsquatting’, it is a type of cyber attack where bad actors create fake packages containing malicious code that is inadvertently added to legitimate code.

However, unlike other forms of digital squatting, in this case, the attackers use packages that are hallucinated by large language models (LLMs). This means increased risks of attack, as all it takes is a programmer running code generated by an LLM without first evaluating and validating it.

Leave a Comment