Evidence · DiggingBeagle record

What is Slopsquatting? The AI Package Hallucination Attack Already Happening

Aikido defines slopsquatting as registering package names that models tend to hallucinate and waiting for developers or agents to install them. It connects the Lasso huggingface-cli and react-codeshift precursor cases to the threat model, and discusses the malicious npm package unused-imports. Crucially, Aikido says packages such as unused-imports are consistent with slopsquatting patterns but that attacker intent behind the names cannot be proved.

Published
Feb 20, 2026
Publisher
Aikido Security

Evidence record

Aikido defines slopsquatting as registering package names that models tend to hallucinate and waiting for developers or agents to install them. It connects the Lasso huggingface-cli and react-codeshift precursor cases to the threat model, and discusses the malicious npm package unused-imports. Crucially, Aikido says packages such as unused-imports are consistent with slopsquatting patterns but that attacker intent behind the names cannot be proved.

Read the original source ↗