Aikido researcher Charlie Eriksen found more than 200 GitHub repositories referring to `npx react-codeshift` even though no npm package by that name existed. By the time he defensively registered the name on January 14, 2026, Aikido counted 237 repositories carrying the reference. Eriksen traced the pattern to an October 17, 2025 commit in wshobson/agents…
Inspect the ClaimsCase · DiggingBeagle record
A hallucinated react-codeshift command spread through Agent Skills and reached real npm fetches
Aikido traced a nonexistent npm package name, react-codeshift, to LLM-generated Agent Skills that spread across 237 GitHub repositories. After a researcher defensively registered the empty name, persistent downloads appeared, providing a real-world precursor to slopsquatting without a malicious payload or confirmed victim compromise.
The case covers the propagation of the nonexistent npm identifier react-codeshift through AI Agent Skills, its defensive registration by Aikido researcher Charlie Eriksen on January 14, 2026, and the subsequent download telemetry. It does not classify the event as a malware campaign because the registered package was an empty defensive placeholder and Aikido explicitly reports that no one was compromised.
At a glance
The important boundary is the transition from generated text to a resolver with execution authority. A hallucinated identifier can remain harmless in a chat transcript, then become operational when it is copied into an Agent Skill and handed to `npx`. Preventing dependency lifecycle scripts does not authenticate that identifier, and a command explicitly…
Read the implicationsThe public Aikido report does not identify the exact model that generated the original react-codeshift instructions. Aikido attributes the persistent post-registration downloads to agents following copied skills, but public npm download counts do not independently identify every requester. Because the registered package was an empty defensive placeholder,…
Limits and uncertaintyFull account
Aikido researcher Charlie Eriksen found more than 200 GitHub repositories referring to npx react-codeshift even though no npm package by that name existed. By the time he defensively registered the name on January 14, 2026, Aikido counted 237 repositories carrying the reference. Eriksen traced the pattern to an October 17, 2025 commit in wshobson/agents that added 47 LLM-generated Agent Skills; at least two of those skills instructed agents to run react-codeshift commands. The name plausibly conflated the real jscodeshift and react-codemod projects.
After the empty defensive package was published, Aikido observed a persistent 1 to 4 downloads per day and interpreted the pattern as agents following the copied skill instructions. That is stronger than a benchmark-only hallucination because the identifier survived inside reusable agent instructions and reached a live resolver. The attribution still has a limit: public npm download telemetry does not independently identify every requester, so the Case should describe agent execution attempts as Aikido's interpretation rather than as per-download proof.
Current npm behavior narrows but does not remove this attack surface. npm v12 blocks unapproved dependency lifecycle scripts by default, while npm's own npm exec and npx documentation still defines those commands as mechanisms for resolving a package and running a command from it. The react-codeshift skills invoked npx directly. A safe placeholder occupied the namespace here, so the incident demonstrates propagation and resolution attempts without malicious execution or victim compromise.
Claims & evidence
CLM-REACT-CODESHIFT-SPREADAikido reports that the nonexistent npm identifier react-codeshift appeared in an October 2025 commit adding 47 LLM-generated Agent Skills, with at least two skills instructing agents to invoke it, and that the reference spread to 237 GitHub repositories before defensive registration.supported
Basis: reported finding
- supportsAgent Skills Are Spreading Hallucinated npx Commandsrole not specified
Sections 'Enter react-codeshift' and 'The origin story', including the 237-repository count, commit 65e5cb0, the 47 LLM-generated skills and the affected react-modernization and react-state-management skills.
CLM-REACT-CODESHIFT-FETCHESAfter defensive registration, Aikido observed a persistent 1 to 4 react-codeshift downloads per day and interpreted the pattern as agents following copied skill instructions and triggering npx resolution; public download telemetry does not independently identify each requester.supported
Basis: reported finding
- supportsAgent Skills Are Spreading Hallucinated npx Commandsrole not specified
Section 'Proof of active execution attempts', including the download telemetry and the researcher's interpretation of the traffic.
CLM-REACT-CODESHIFT-NO-COMPROMISEThe defensively registered react-codeshift package was harmless, and Aikido reports that the episode did not produce a breach or compromised victim.supported
Basis: direct observation
- supportsAgent Skills Are Spreading Hallucinated npx Commandsrole not specified
Section 'Why this matters', where the researcher states that the package is a safe placeholder and that nobody was compromised.
Implications
The important boundary is the transition from generated text to a resolver with execution authority. A hallucinated identifier can remain harmless in a chat transcript, then become operational when it is copied into an Agent Skill and handed to npx. Preventing dependency lifecycle scripts does not authenticate that identifier, and a command explicitly executed through npm exec or npx still needs an independent package-identity decision.
The case therefore supports two separate controls: resolve and verify the requested resource before execution, then constrain what the execution context can access. Either control can reduce consequence even if the model continues to hallucinate package names.
Unknowns and contradictions
- The public Aikido report does not identify the exact model that generated the original react-codeshift instructions.
- Aikido attributes the persistent post-registration downloads to agents following copied skills, but public npm download counts do not independently identify every requester.
- Because the registered package was an empty defensive placeholder, the case does not demonstrate malicious code execution, credential theft or financial loss.
- The public evidence does not establish how many environments would have executed an attacker-controlled package successfully if the namespace had been malicious rather than defensive.
Sources and citation
Material revision history
- Oct 7, 2026 · Canonical change recorded · new in release · revision 88