Evidence · DiggingBeagle record
What is Slopsquatting? The AI Package Hallucination Attack Already Happening
Aikido defines slopsquatting as registering package names that models tend to hallucinate and waiting for developers or agents to install them. It connects the Lasso huggingface-cli and react-codeshift precursor cases to the threat model, and discusses the malicious npm package unused-imports. Crucially, Aikido says packages such as unused-imports are consistent with slopsquatting patterns but that attacker intent behind the names cannot be proved.
- Published
- Feb 20, 2026
- Publisher
- Aikido Security
Evidence record
Aikido defines slopsquatting as registering package names that models tend to hallucinate and waiting for developers or agents to install them. It connects the Lasso huggingface-cli and react-codeshift precursor cases to the threat model, and discusses the malicious npm package unused-imports. Crucially, Aikido says packages such as unused-imports are consistent with slopsquatting patterns but that attacker intent behind the names cannot be proved.