When Your Coding Assistant Invents a Package, Attackers Register It First

Ask an AI coding assistant to clean up imports and it may hand you a package name that does not exist. The name will look plausible. It will combine two real tools, or follow a naming convention you recognize. You paste the install command, and if someone has already registered that name, you have just installed whatever they published.
Security researchers call this slopsquatting. It is a relative of typosquatting, except the attacker does not need you to mistype anything. They only need to know what the model tends to invent, and then be the first to claim it.
The scale is not anecdotal
A 2025 USENIX Security study tested 16 code-generating models on 576,000 code samples in Python and JavaScript. It found more than 205,000 unique package names that did not exist on any registry. The hallucination rate was at least 5.2% for commercial models and 21.7% for open-source ones. A 2026 follow-up tested five newer frontier models and measured rates between 4.62% and 6.10%, which is lower but still present in every model tested.
The part that turns a quirk into an attack surface is repeatability. When the researchers reran identical prompts, a large share of the hallucinated names came back every time. Models are not guessing randomly; they converge on the same wrong answers because they learned the same patterns from the same training data. That predictability is the vulnerability. An attacker can run the same prompts, collect the names that repeat, and register them before anyone else.
The 2026 study identified 127 package names that all five tested models produced despite not existing, with 53 still available for registration after registry protections were applied.
Real packages, real installs
This has already happened. Early in 2026, researchers found a package called react-codeshift referenced across 237 GitHub repositories. The name blends two real tools, jscodeshift and react-codemod. It had never been published. An AI-generated skill containing the fictional package had been copied and forked, letting the reference spread on its own.
A package called metro-evaluator on npm carried malicious code in four versions published in December 2025 before it was removed five days later and replaced with a security placeholder. The tested models had suggested that name ten times. Another, unused-imports, mimicked the real eslint-plugin-unused-imports and kept collecting installs from developers whose assistant pointed them at it.
The bigger operation is a campaign the security firm Koi Security calls PhantomRaven, active since at least August 2025. Koi attributes 126 malicious npm packages and more than 86,000 downloads to it. The trick there is different from a hallucinated name. The package.json looks clean, sometimes containing little more than a log line, but it points to a dependency hosted at a plain HTTP URL rather than another npm package. Most scanners do not follow raw URLs, so the payload that harvests npm tokens, GitHub credentials and CI secrets loads invisibly at install time. Endor Labs documented three further waves of the same campaign between November 2025 and February 2026, adding 88 more packages uploaded through roughly 50 disposable accounts.
Registries blocked most of the names, not all of them
There is one piece of good news in the research. Package registries have gotten better at blocking the names models tend to invent. They normalize similar names, maintain prohibition lists, and watch for the patterns that show up across many generated samples. When the 2026 study checked its list of 127 shared hallucinated names, most had already been claimed or blocked by legitimate projects and registry defenses.
The problem is that "most" is not "all." The same study found 53 names still available for registration after protections were applied. A single registrable name that several frontier models agree on is enough to build an attack around, because the attacker only needs to guess the model, not the developer. The registry operators have closed most of the door; the remaining gap is narrow but open.
The same pattern has now spread beyond package managers. Security researchers have documented attackers registering domains that models hallucinate, and repositories and skills that agents are likely to invent. The mechanism is identical in each case: a model predicts a plausible name, and a system built to trust that prediction acts on it. Every new surface an agent can reach becomes another place to plant a name the agent will reach for.
Why agents make it worse
A human developer might notice a suspicious package name. An agent will not. Agents install dependencies autonomously, often without a human reading the command first. Researchers have demonstrated prompt-injection techniques that trick agents into requesting attacker-controlled package names, with reported success rates up to 100% on tools including Cursor, Windsurf and GitHub Copilot.
That combination is what changed the risk profile. The hallucination provides the name. The agent provides the execution. The attacker only has to wait for the two to meet.
The leak problem is the same problem
A related report from the firm Glow found agents exposing more than 13,000 internal images on GitHub, drawn from over 300 organizations. The mechanism is mundane: agents and their users put screenshots, diagrams and documents into public repositories, sometimes without understanding that "public" means searchable and permanent. The same tools that make developers faster also make it easier to move internal material somewhere it should not go.
Both issues share a root cause. Agents act at machine speed on instructions that may be wrong (a hallucinated name) or sensitive (an internal screenshot). The human checkpoint that used to sit between intent and action is exactly what the agent removes.
What to actually do
The defenses are not complicated, which is good news given how quickly the threat moved.
Treat every install command an agent produces as untrusted input. Check the package exists before installing it. Check how old it is; a hallucinated name that has been registered will be young. Check the publisher has a history. For npm and PyPI, a quick metadata lookup answers all three questions in seconds.

Require human approval before an agent adds a dependency. This is the single highest-value change, because it catches the hallucinated names, the malicious registrations and the prompt-injected requests at once. It slows the agent a little and closes the largest hole.
Keep the agent's reach small. A coding agent needs repository access; it rarely needs production credentials, and it should not have a package manager pointed at a private registry without a check. Tools like Socket and Snyk can automate the registry lookup inside the IDE or the CI pipeline, which is worth the cost once a team is using agents across many repositories.
The uncomfortable part is that none of this is a bug that gets patched. Hallucination is baked into how these models predict text: they generate the next plausible name, not a verified one. The fix has to live in the workflow around the model, and that is a process most teams can start this week.
Related articles
Salesforce Pays $2 Billion for a Company That Interviews Your Customers For You
Interviews are evidence. Digital twins are a prediction. The line between them is the test.
AMD Buys Fei-Fei Li's World Labs for $8.2 Billion to Own Physical AI
AMD is buying a research lab, and paying a chipmaker's price for it.
Google Put a TPU in Orbit and Started Counting the Cost of Space Data Centres
One working chip proves the trip is survivable. It says little about the profit.
Someone Catalogued 13,000 Ways AI Writing Gives Itself Away
The tells did not disappear. They moved somewhere harder to see.