← Founder Notes
Archive

Typosquatting bet on a typo; slopsquatting bets on your ai assistant. research now shows nearly one…

Yethikrishna ROriginal on Threads

typosquatting bet on a typo; slopsquatting bets on your ai assistant. research now shows nearly one in five ai-recommended packages doesn't exist, attackers preregister those hallucinated names, and confirmed real-world packages have racked up tens of thousands of downloads.

the supply chain risk is a name the model invented.

Context

Dark Reading of 14 April 2025 reports a study of 576,000+ code samples from 16 models, by researchers at UTSA, Oklahoma and Virginia Tech, finding 21.7% of package names from open-source models were hallucinated and 5.2% for commercial models, with 205,474 unique invented names. An arXiv paper, 2605.17062, replicates it on five frontier models released from October 2025 to March 2026 across 199,845 prompts and finds hallucination rates of 4.62% to 6.10%, calls it an order-of-magnitude compression of the spread and not a retirement of the threat, and finds 53 registrable names, 41 on PyPI and 12 on npm. Snippets describe a Lasso Security proof of concept in which a hallucinated name, huggingface-cli, was registered empty and downloaded, and Aikido noting malicious packages consistent with the pattern while saying it cannot prove what attackers intend.

How it compares

Nearly one in five is not supported as stated. The 2025 figure of 21.7% is for open-source models only, with 5.2% for commercial ones, and it is a share of package names in generated code samples, so it is not a rate for all recommended packages, and the 2026 re-evaluation of newer models found about 4.6 to 6.1%. The note presents 2025 open-model data as current. The documented real case is a researcher's proof of concept, not an attacker's, and no text read confirms malicious preregistration with tens of thousands of downloads, so that is unverified. The original paper was not read, only the Dark Reading relay, and who coined slopsquatting was not read. Package hallucination is a real, measured phenomenon.

Watch next

  • Dated download counts for real hallucinated-name packages.

Sources

  1. AI code tools widely hallucinate packages (Dark Reading, 14 Apr 2025)darkreading.com
  2. Package hallucination replication (arXiv 2605.17062)arxiv.org
  3. AI package hallucinations (Lasso Security, 28 Mar 2024)lasso.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 03:06 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/typosquatting-bet-on-a-typo-slopsquatting-bets-on-Dde_bYcFyvV" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Typosquatting bet on a typo; slopsquatting bets on your ai assistant. research now shows nearly one…"></iframe>

More notes