Case · DiggingBeagle record

A hallucinated react-codeshift command spread through Agent Skills and reached real npm fetches

Aikido traced a nonexistent npm package name, react-codeshift, to LLM-generated Agent Skills that spread across 237 GitHub repositories. After a researcher defensively registered the empty name, persistent downloads appeared, providing a real-world precursor to slopsquatting without a malicious payload or confirmed victim compromise.

Scope

The case covers the propagation of the nonexistent npm identifier react-codeshift through AI Agent Skills, its defensive registration by Aikido researcher Charlie Eriksen on January 14, 2026, and the subsequent download telemetry. It does not classify the event as a malware campaign because the registered package was an empty defensive placeholder and Aikido explicitly reports that no one was compromised.

UnratedAI role: WITH AIAssessment method

At a glance

Claims & evidence

CLM-REACT-CODESHIFT-SPREADAikido reports that the nonexistent npm identifier react-codeshift appeared in an October 2025 commit adding 47 LLM-generated Agent Skills, with at least two skills instructing agents to invoke it, and that the reference spread to 237 GitHub repositories before defensive registration.supported

Basis: reported finding

  • supports
    Agent Skills Are Spreading Hallucinated npx Commandsrole not specified

    Sections 'Enter react-codeshift' and 'The origin story', including the 237-repository count, commit 65e5cb0, the 47 LLM-generated skills and the affected react-modernization and react-state-management skills.

Link to claim
CLM-REACT-CODESHIFT-FETCHESAfter defensive registration, Aikido observed a persistent 1 to 4 react-codeshift downloads per day and interpreted the pattern as agents following copied skill instructions and triggering npx resolution; public download telemetry does not independently identify each requester.supported

Basis: reported finding

Link to claim
CLM-REACT-CODESHIFT-NO-COMPROMISEThe defensively registered react-codeshift package was harmless, and Aikido reports that the episode did not produce a breach or compromised victim.supported

Basis: direct observation

Link to claim

Implications

The important boundary is the transition from generated text to a resolver with execution authority. A hallucinated identifier can remain harmless in a chat transcript, then become operational when it is copied into an Agent Skill and handed to npx. Preventing dependency lifecycle scripts does not authenticate that identifier, and a command explicitly executed through npm exec or npx still needs an independent package-identity decision.

The case therefore supports two separate controls: resolve and verify the requested resource before execution, then constrain what the execution context can access. Either control can reduce consequence even if the model continues to hallucinate package names.

Unknowns and contradictions

  • The public Aikido report does not identify the exact model that generated the original react-codeshift instructions.
  • Aikido attributes the persistent post-registration downloads to agents following copied skills, but public npm download counts do not independently identify every requester.
  • Because the registered package was an empty defensive placeholder, the case does not demonstrate malicious code execution, credential theft or financial loss.
  • The public evidence does not establish how many environments would have executed an attacker-controlled package successfully if the namespace had been malicious rather than defensive.

Sources and citation

Material revision history

  1. Oct 7, 2026 · Canonical change recorded · new in release · revision 88