AI Package Hallucinations Slopsquatting Attack Vector
AI Package Hallucinations Slopsquatting Attack Vector TL;DR AI agents hallucinate identical fake package names predictably, with suffixes like -pro, -turbo, -easy appearing across 161 verified cases Slopsquatting attackers pre-register these hallucinated names on PyPI, npm, and 17 other ecosystems to exploit AI-driven development workflows DepScope provides free API-driven pre-installation validation across 19 package ecosystems with … Read more