Back to blog

Blog Post

Slopsquatting Supply Chain Threat

Share on social

Apr 17, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Slopsquatting Supply Chain Threat

[Slopsquatting Supply Chain]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon

Security researchers are raising concerns about a potential supply chain cybercrime tactic involving Generative AI, called “Slopsquatting.” This technique exploits a known flaw in GenAI tools - hallucinations, where the AI generates false or non-existent information. In terms of software development, this can include entirely fabricated open-source packages.

Socket reports that many developers now rely on GenAI tools like ChatGPT and GitHub Copilot to assist with coding. These tools can write code directly or recommend packages to include in a project. The issue arises when AI suggests packages that don’t actually exist. According to the research, when the same prompt was run ten times, 43 percent of hallucinated packages appeared every time, while 39 percent never showed up again.

“Overall 58 percent of hallucinated packages were repeated more than once across ten runs,” the report notes, “indicating that a majority of hallucinations are not just ransom noise, but repeatable artifacts of how the models respond to certain prompts.”

At this stage, Slopsquatting is theoretical, with no known attacks. However, the threat is real - cybercriminals could monitor GenAI hallucination, identify the most commonly suggested fake packages, and register them on Open-Source repositories. This means unsuspecting developers could be tricked into downloading and using malicious software.

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

August 20, 2026

Beacon: Cl0p Claims Data Theft from More than 40 Companies

August 19, 2026

wp2shell: Discovering One of 2026’s Biggest Zero-Days, and the Future of Exposure Management

August 14, 2026

Beacon: OpenAI's Astra Paused Due to Hacking Use Concerns

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient