Topic · DiggingBeagle record
Slopsquatting
A software supply-chain attack pattern in which an attacker registers a package or resource identifier that an AI system is likely to invent, then relies on a developer or agent to fetch the attacker-controlled resource when the hallucination recurs.
Definition & limits
Slopsquatting is a supply-chain attack pattern in which an attacker occupies a package, repository or skill identifier that an AI system is likely to invent, then waits for a later developer or agent to resolve that identifier. The attack depends on more than hallucination frequency. Four conditions have to line up: the invented identifier must recur often enough to be predictable; the namespace must still be registrable; the resolver must accept the identifier without an independent identity check; and the caller must have enough authority to fetch or execute the resolved resource.
The evidence should be tracked as separate stages. Stage one is a repeatable hallucination. Stage two is attacker or defensive registration of the vacant name. Stage three is a real fetch or install attempt. Stage four is malicious execution. Stage five is demonstrated impact such as credential theft, wallet-key exfiltration or code execution. Evidence for one stage does not prove the next.
The 2025 USENIX package-hallucination study is important because it measured both recurrence and concentration. It reported that 58% of hallucinated package names reappeared within ten iterations, while 81% of hallucinated names were produced by only one tested model. That means an attacker can sometimes mine a particular model for stable mistakes, but a name hallucinated by one model should not automatically be treated as a universal lure. A 2026 frontier-model preprint found a smaller set of 127 names shared across all five tested models and later reported that 53 of those common names were still registrable, showing that cross-model overlap can exist without making it the baseline assumption.
Slopsquatting differs from typosquatting because the victim does not mistype a known package; the model fabricates the lookup key. It differs from brandjacking because the attacker does not need to imitate a famous package. It differs from a compromised legitimate dependency because the attacker begins with a previously vacant namespace. It also differs from malicious skills that are intentionally published and discovered by normal search, and from plugin-integrity failures such as Plugin4Shell, where a trusted identifier resolves to attacker-controlled code despite an attempted pin.
Mitigations map to those stages. Search or authoritative registry resolution before fetch can prevent many nonexistent identifiers from becoming install actions; the 2026 HalluSquatting experiments found a large reduction in repository hallucination when search preceded clone, but no prompt wording was universally safe. Provenance and publisher checks help after an identifier exists. Immutable artifact verification matters after resolution. Package-manager controls such as npm v12's default blocking of unapproved dependency lifecycle scripts reduce automatic execution, but they do not authenticate the package name and do not remove explicit npm exec or npx execution. Finally, isolating installers from secrets and irreversible authority reduces the damage when every earlier check fails.
Examples
- react-codeshift: an LLM-generated Agent Skill propagated a nonexistent npm command across 237 repositories. A researcher defensively registered the name and observed persistent downloads. This demonstrates propagation and real resolution attempts, but no malicious payload or victim compromise.
- huggingface-cli: Lasso defensively registered a repeatedly hallucinated Python package name and reported more than 30,000 downloads over three months. The experiment demonstrates adoption of a hallucinated identifier, not attacker compromise.
- Adversarial HalluSquatting: researchers pre-registered likely hallucinated repositories and skills and reached tool execution or code execution in controlled agent experiments. Public squatted resources were kept benign, so this is a feasibility demonstration rather than an in-the-wild campaign.
- Polymarket and TrapDoor are useful counterexamples for classification. Both are real malicious package campaigns with AI-oriented targeting, but the public evidence does not establish that their package identifiers were first hallucinated by a model.