Updated
Updated · InfoWorld · Jul 24
5 AI Models Hallucinate 127 Package Names, Leaving 53 Open to Slopsquatting
Updated
Updated · InfoWorld · Jul 24

5 AI Models Hallucinate 127 Package Names, Leaving 53 Open to Slopsquatting

1 articles · Updated · InfoWorld · Jul 24

Summary

  • Researcher Aleksandr Churilov found 127 nonexistent package names repeated across five coding models—Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro and DeepSeek V3.2.
  • 53 of those names were still unregistered as of April—41 on PyPI and 12 on npm—creating openings for attackers to publish malicious packages that developers might import after AI-generated suggestions.
  • Churilov said the overlap likely comes from shared public training material with bad references and from models independently inventing plausible names that fit package-naming conventions.
  • The paper, which has not been peer-reviewed, found no evidence so far that any of the 53 available names have been maliciously registered or used in an attack.

Insights

Why are the world's most advanced AI models consistently hallucinating the exact same digital backdoors for hackers to exploit?
Could the AI coding assistant you trust today be secretly wiring your enterprise network for a devastating supply-chain attack tomorrow?
If an AI hallucinates a malicious package that destroys your company data, who is ultimately held responsible for the breach?