“Slopsquatting” attacks are using AI-hallucinated names resembling popular libraries to spread malware
- GenAI can hallucinate open source package names, experts warn
- It doesn’t always hallucinate a different name
- Cybercriminals can use the names to register malware
Security researchers have warned of a new method by which Generative AI (GenAI) can be abused in cybercrime, known as ‘slopsquatting’.
It starts with the fact that different GenAI tools, such as Chat-GPT, Copilot, and others, hallucinate. In the context of AI, “hallucination” is when the AI simply makes things up. It can make up a quote that a person never said, an event that never happened, or – in software development – an open-source software package that was never created.
Now, according to Sarah Gooding from Socket, many software developers rely heavily on GenAI when writing code. The tool could write the lines itself, or it could suggest the developer different packages to download and include in the product.
Hallucinating malware
The report adds the AI doesn’t always hallucinate a different name or a different package – some things repeat.
“When re-running the same hallucination-triggering prompt ten times, 43% of hallucinated packages were repeated every time, while 39% never reappeared at all,” it says.
“Overall, 58% of hallucinated packages were repeated more than once across ten runs, indicating that a majority of hallucinations are not just random noise, but repeatable artifacts of how the models respond to certain prompts.”
This is purely theoretical at this point, but apparently, cybercriminals could map out the different packages AI is hallucinating and – register them on open-source platforms.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Therefore, when a developer gets a suggestion and visits GitHub, PyPI, or similar – they will find the package and happily install it, without knowing that it’s malicious.
Luckily enough, there are no confirmed cases of slopsquatting in the wild at press time, but it’s safe to say it is only a matter of time. Given that the hallucinated names can be mapped out, we can assume security researchers will discover them eventually.
The best way to protect against these attacks is to be careful when accepting suggestions from anyone, living or otherwise.
You might also like
GenAI can hallucinate open source package names, experts warn It doesn’t always hallucinate a different name Cybercriminals can use the names to register malware Security researchers have warned of a new method by which Generative AI (GenAI) can be abused in cybercrime, known as ‘slopsquatting’. It starts with the fact…
Recent Posts
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023