Analysis · DiggingBeagle record

The package did not exist until the model invented it

Models sometimes invent package names, and those mistakes can become executable supply-chain paths when agents resolve them automatically. Real-world evidence now reaches live package fetches and controlled code execution, while separate malware campaigns already target AI-assisted developers. What remains unproven is the most dramatic version: one hallucinated package name leading to a documented victim wallet drain.

Published
Oct 7, 2026

Overview

An AI coding agent can turn a made-up package name into a real software dependency.

The mechanism is simple enough to miss. A model recommends a plausible package that does not exist. The name is copied into code, documentation or an Agent Skill. Someone later registers that vacant name. When another developer or agent follows the same recommendation, the package manager no longer sees a hallucination; it sees a real package controlled by whoever claimed the namespace.

That attack pattern is slopsquatting. The public evidence now supports several pieces of the chain, including repeatable hallucinated identifiers, real resolver traffic and controlled code execution. It does not yet support the most dramatic social-media version in one documented incident: a frontier model invents a package, an attacker registers that exact name with malware, a victim installs it because of the model recommendation, and money is then shown leaving the victim's wallet.

A hallucination becomes dangerous only after another system trusts it

Package hallucinations are not rare measurement noise. A peer-reviewed USENIX Security 2025 study generated 576,000 Python and JavaScript samples across 16 models and reported hallucinated-package rates of at least 5.2% for commercial models and 21.7% for open-source models. It identified 205,474 unique nonexistent package names.

The more important result for an attacker was repetition. The study found that 58% of hallucinated package names reappeared within ten iterations. A mistake that repeats can be mined: an attacker can ask a model for packages, collect names that do not exist, register the promising ones and wait.

The same study also found that 81% of hallucinated package names appeared in only one tested model. That limits a common exaggeration. Slopsquatting does not require every model to invent the same name, and one model's mistake should not be treated as a universal lure.

A 2026 preprint repeated the broad experiment on five newer frontier models and reported overall hallucination rates between 4.62% and 6.10%. It found 127 package names invented by all five tested models. The work is not directly comparable with the USENIX cohort, but it shows that newer models have not removed the underlying namespace problem.

The security boundary appears later: when a generated string is handed to a resolver that is allowed to fetch or execute it.

`react-codeshift` crossed that boundary

The clearest public precursor is the react-codeshift case.

Aikido researcher Charlie Eriksen found GitHub repositories containing npx react-codeshift, although no npm package by that name existed. Aikido traced the reference to an October 2025 commit containing 47 LLM-generated Agent Skills, with at least two skills instructing agents to invoke the nonexistent package.

By January 2026, Aikido counted the reference in 237 repositories. Eriksen then defensively registered the empty npm name. After registration, the package received a persistent 1 to 4 downloads per day.

Nothing malicious happened because the researcher occupied the namespace with a harmless placeholder. Aikido also says nobody was compromised. The download telemetry does not independently identify every requester, so the claim that agents were responsible remains Aikido's interpretation of the pattern rather than a per-download identity record.

Even with that qualification, the incident matters. The hallucination did not remain inside a chat. It survived in reusable Agent Skills, propagated through repositories and eventually resolved through npm after the namespace became real.

That is the critical transition.

Controlled HalluSquatting shows what happens when the resource is malicious

A July 2026 research paper pushed the mechanism further by testing hallucinated repositories and skills against production LLM applications with terminal access.

The researchers estimated identifiers that agents were likely to invent, registered the corresponding resources and tested what happened when an agent resolved them. In controlled experiments, attacker-controlled hallucinated resources reached remote tool execution and remote code execution.

This closes an important technical gap between "the model invented a name" and "the machine executed attacker-controlled behavior." It does not prove an in-the-wild botnet or a public victim campaign. The malicious stages were controlled research, while publicly reachable squatted resources were kept benign.

The same research also tested a useful defensive change. In its Cursor CLI experiment, requiring search before cloning sharply reduced repository hallucination compared with the no-search condition. That is evidence for checking resource identity before resolution, not evidence that web search makes agents generally safe.

Real malicious packages already target AI-assisted developers

Other 2026 campaigns demonstrate the consequence side of the equation, but through different mechanisms.

The Polymarket package campaign used nine malicious npm packages that imitated Polymarket tooling. Two names, polymarket-claude-code and polymarket-ai-agent, were explicitly tailored to AI-assisted development.

SafeDep found a shared payload that could collect an Ethereum private key from local environment data or an interactive onboarding flow and send the raw key to attacker infrastructure. The install path had prerequisites, including an interactive terminal for the onboarding flow, and current npm protections can block unapproved dependency lifecycle scripts.

The campaign still demonstrates something important: packages presented as useful AI-development tools can be built to exfiltrate wallet keys. What it does not demonstrate is slopsquatting. The public evidence does not show a model inventing those package names before the attacker registered them, nor does it document a victim wallet drain caused by an AI recommendation.

TrapDoor crossed another boundary. Socket linked more than 34 malicious packages across npm, PyPI and Crates.io to a campaign that posed as developer, security, crypto and AI tooling. The packages targeted credentials and wallet material through ecosystem-specific execution paths.

TrapDoor also planted hidden instructions in .cursorrules and CLAUDE.md, surfaces that coding assistants may read as operational context. Socket documented campaign-linked attempts to place those AI-facing files into legitimate projects.

That is not slopsquatting either. The attacker did not need the model to invent the package name. Instead, the package and repository were designed to look relevant to an AI-assisted workflow, while the AI-facing files created a second trust surface after installation.

Similar package attacks fail at different boundaries

Pattern What the attacker controls Where AI matters What is demonstrated What is not
Slopsquatting A vacant package, repository or skill name likely to be hallucinated The model or agent produces the identifier Real resolver traffic in react-codeshift; code execution in controlled HalluSquatting research A public malicious victim case with documented financial loss
AI-targeted package masquerading A deliberately plausible malicious package The package name and workflow are tailored to AI-assisted development Private-key exfiltration capability in the Polymarket packages Proof that a model hallucinated or recommended the name
Package plus AI-instruction poisoning A malicious dependency and AI-facing project instructions The assistant later reads attacker-controlled context TrapDoor package malware and observed .cursorrules / CLAUDE.md planting A measured successful-compromise rate across assistants
Plugin integrity failure A trusted plugin identity whose resolution can be subverted The agent installs or updates the plugin Plugin4Shell demonstrated attacker-controlled code despite attempted pinning No hallucinated identifier is required
Malicious skill publication A skill that already exists in a marketplace The agent chooses or trusts the published skill OpenClaw malicious skills abused inherited local authority No hallucinated namespace is required

The distinction is operational, not semantic. Each mechanism needs a different control.

The package manager is where the model's guess becomes authority

Better model accuracy helps because fewer invented names enter the pipeline. It cannot be the only control.

Before fetching a package, repository or skill, an agent can check whether the resource exists, who publishes it, how old it is, whether the expected source repository matches, and whether the artifact is the exact object that policy allows. Those checks have to happen outside the model's free-form confidence.

Execution is a separate boundary. npm v12 blocks unapproved dependency lifecycle scripts by default, which removes one automatic malware path. It does not authenticate a package name, and explicit npm exec or npx use can still resolve and run the selected package. Other ecosystems have different execution paths, including import-time Python behavior and Rust build scripts.

Secrets are another boundary. A package installed in an environment with wallet keys, cloud credentials, GitHub tokens or signing authority can turn one bad resolution decision into a much larger incident. Removing those secrets from the install context changes the consequence even when the earlier identity check fails.

AI-facing project files need the same treatment. Skills, .cursorrules, CLAUDE.md and similar files may look like documentation to a human reviewer, but an agent can treat them as instructions that affect later tool calls.

The strongest evidence therefore supports a narrower statement than the viral version: models invent resource names, some of those mistakes repeat, real agent workflows have resolved defensively registered hallucinated names, and controlled research shows that attacker-controlled hallucinated resources can reach code execution. Separate malicious package campaigns already steal keys and credentials from AI-oriented developer workflows.

The missing join remains important. There is still no strong public evidence in this research set for one incident that connects a frontier-model hallucination, attacker registration of that exact name, model-caused victim installation and a documented wallet drain.

That absence does not make the mechanism hypothetical. It tells us exactly which parts have been observed, which have been demonstrated under controlled conditions, and which claims still outrun the evidence.

Research behind this