The Slopsquatting Trap: How AI Mistakes Are Weaponized by Hackers
Expert: Harry Swain
Role: SOC Analyst
Specialises in: Security Operations
Table of Contents
What is Slopsquatting?
Slopsquatting is a newly emerging attack vector gaining traction alongside the rise of AI coding tools like GitHub Copilot and ChatGPT. In simple terms, it occurs when attackers exploit hallucinated package names – that is, fake or non-existent libraries suggested by AI tools – to deliver malware and compromise the software supply chain.
This technique is a twist on typosquatting. But instead of relying on human typing errors, slopsquatting leverages the mistakes made by AI. The term itself combines โslopโ (a derogatory reference to low-quality AI output) with โsquattingโ (the act of occupying a name or resource for malicious use).
Slopsquatting was recently analysed in depth by researchers from the University of Texas at San Antonio, Virginia Tech, and the University of Oklahoma, who reviewed how AI hallucinations are exploited to inject malicious packages into software supply chains (Spracklen et al., 2025). This intel draws on that research to provide a clear, practical summary of the threat and how to defend against it โ keep reading for more.
How Slopsquatting Works
To understand how attackers take advantage of this AI-driven threat, itโs helpful to look at how slopsquatting typically plays out in the wildโฆ
- AI Hallucination: When developers use AI coding assistants such as GitHub Copilot, ChatGPT, or open-source LLMs like CodeLlama, these tools may recommend fictitious package names that sound plausible but donโt exist in repositories like PyPI (Python Package Index) or npm (Node Package Manager).
- Malicious Registration: Attackers monitor these hallucinated package names, register them in public package registries, and upload malicious code under those names.
- Exploitation: Developers, trusting the AIโs suggestions, unknowingly install these malicious packages, which can steal data, deploy malware, or compromise software supply chains.
Key Characteristics of SlopSquating
The 2025 research from the University of Texas at San Antonio, Virginia Tech, and the University of Oklahoma sheds light on why Slopsquatting is so concerning, and these core characteristics help explain its appeal to attackers and the risks to development teams.
Recent Slopsquatting Cases and Trends
While no large-scale slopsquatting attacks have been widely reported as of April 2025, the threat is gaining attention:
Slopsquatting Mitigation Strategies
Fortunately, there are practical steps developers and organisations can take to reduce the risk. Below are five key mitigation strategies informed by current research and best practices.
Their agility allows them to bypass many standard security controls, especially where user trust and session persistence are not well managed.
The Main Takeaway
Slopsquatting may seem niche, but it Slopsquatting is particularly dangerous because it exploits the growing reliance on AI coding tools in fast-paced development environments.
With “vibe coding” where developers describe tasks and let AI generate code, the risk of installing unverified packages increases. If a widely recommended hallucinated package is weaponised, it could lead to widespread supply chain attacks, potentially compromising financial institutions, critical infrastructure, or sensitive data.
As AI adoption accelerates, so does the attack surface. Now is the time for development teams, CISOs, and security leads to get ahead of the risk.
Looking for cyber security support for your organisation? Book a free discovery session with us, our experts are here to help – no jargon, just clear, strategic guidance.










