Blog · AI and security
One in five AI code snippets imports packages that don't exist. Attackers are already registering them
The Cloud Security Alliance documents slopsquatting: models make up library names, someone publishes a malicious package under one of those names, and the next install pulls it in. Reviewing dependencies is no longer red tape.

What the research found
The Cloud Security Alliance research note, published in April 2026, draws on a study presented at USENIX Security 2025 that analyzed 576,000 code snippets generated by 16 language models. About 20% referenced packages that don't exist.
What makes the problem exploitable is repetition. Of those made-up names, 43% showed up consistently for similar prompts, and 58% came back at least once across ten runs. A hallucinated name is predictable, and whoever predicts it can publish it first.
How it becomes an attack
Slopsquatting means registering those names as real packages before someone installs them. The note cites a confirmed case: a malicious package called "unused-imports" ran scripts at install time that were designed to steal credentials and API keys.
It also cites an experiment: a hallucinated package name, published with no code and no README, racked up more than 30,000 downloads in three months. It's a variant of typosquatting, with one difference: instead of waiting for a person to make a typo, the attacker counts on a model making up the same name for many users.