🛠️Slopsquatting: AI Agent Recommends a Malware Package
TL;DR
An AI agent at consultancy Softjourn recommended a plausible-sounding package created days earlier with almost no downloads. Attackers now register the exact names models hallucinate, a supply-chain trick called slopsquatting.
An AI agent at consultancy Softjourn recommended a plausible-sounding package created days earlier with almost no downloads. Attackers now register the exact names models hallucinate, a supply-chain trick called slopsquatting. The developer caught it only because policy required reading the source.

Key Points
Reported by Sergiy Fitsak, managing director at software consultancy Softjourn
The recommended package was formatted like a familiar library but was days old with few downloads
Slopsquatting: attackers register real packages under names LLMs invent, betting devs install first
Softjourn policy requires checking download counts and GitHub source before any AI-recommended install
Payload was never identified; a backdoor or data theft was the plausible outcome
Why It Matters
Every coding agent in your org is an unvetted package recommender, and a two-minute source check is currently the only control that reliably catches this class of supply-chain attack.
Quick Facts
Frequently Asked Questions
Why does this matter?
Every coding agent in your org is an unvetted package recommender, and a two-minute source check is currently the only control that reliably catches this class of supply-chain attack.
What happened?
An AI agent at consultancy Softjourn recommended a plausible-sounding package created days earlier with almost no downloads. Attackers now register the exact names models hallucinate, a supply-chain trick called slopsquatting.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,249 builders reading daily.