chiprook
← Security
SecuritySeptember 30, 2026, 07:15

VDB: 83 of 87 AI-hallucinated package names are unclaimed, exposing slopsquatting risk

VDB re-checked the 100 highest-risk package names recommended by Claude, GPT and Gemini: 87 passed registry naming rules, all 87 returned 404, and 83 belong to nobody and can be registered by anyone. This leaves the door open to slopsquatting, where an attacker claims a hallucinated name and ships malicious code to the next developer or coding agent.

VDB: 83 of 87 AI-hallucinated package names are unclaimed, exposing slopsquatting risk
#OpenAI#Anthropic#Google#Npm
Read next
Security

101 Malicious npm Packages Add Developers to WhatsApp Groups Without Consent

Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials

Security

Malicious npm packages evade install-script defenses at runtime