TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
Sergio Morales
Wednesday, 16 April 2025 / Published in Uncategorized

Developers Beware: Slopsquatting & Vibe Coding Can Increase Risk of AI-Powered Attacks

Zoomed in monitor with programming.

Contents
  • What is slopsquatting?
  • AI-hallucinated software packages are on the rise
    • Must-read security coverage
  • How vibe coding might increase this security risk
  • How developers can protect themselves

Security researchers and developers are raising alarms over “slopsquatting,” a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like GitHub Copilot, ChatGPT, and DeepSeek, attackers are exploiting AI’s tendency to invent software packages, tricking users into downloading malicious content.

What is slopsquatting?

The term slopsquatting was originally coined by Seth Larson, a developer with the Python Software Foundation, and later popularized by tech security researcher Andrew Nesbitt. It refers to cases where attackers register software packages that don’t actually exist but are mistakenly suggested by AI tools; once live, these fake packages can contain harmful code.

Patrocinado por TecnoArtesanos ¿Tu empresa ya está usando IA? Automatizamos procesos, integramos asistentes inteligentes y conectamos tus sistemas. Descubre cómo →

If a developer installs one of these without verifying it — simply trusting the AI — they may unknowingly introduce malicious code into their project, giving hackers backdoor access to sensitive environments.

Unlike typosquatting, where malicious actors count on human spelling mistakes, slopsquatting relies entirely on AI’s flaws and developers misplaced trust in automated suggestions.

AI-hallucinated software packages are on the rise

This issue is more than theoretical. A recent joint study by researchers at the University of Texas at San Antonio, Virginia Tech, and the University of Oklahoma analyzed more than 576,000 AI-generated code samples from 16 large language models (LLMs). They found that nearly 1 in 5 packages suggested by AI didn’t exist.

“The average percentage of hallucinated packages is at least 5.2% for commercial models and 21.7% for open-source models, including a staggering 205,474 unique examples of hallucinated package names, further underscoring the severity and pervasiveness of this threat,” the study revealed.

Even more concerning, these hallucinated names weren’t random. In multiple runs using the same prompts, 43% of hallucinated packages consistently reappeared, showing how predictable these hallucinations can be. As explained by the security firm Socket, this consistency gives attackers a roadmap — they can monitor AI behavior, identify repeat suggestions, and register those package names before anyone else does.

The study also noted differences across models: CodeLlama 7B and 34B had the highest hallucination rates of over 30%; GPT-4 Turbo had the lowest rate at 3.59%.

Must-read security coverage

How vibe coding might increase this security risk

A growing trend called vibe coding, a term coined by AI researcher Andrej Karpathy, may worsen the issue. It refers to a workflow where developers describe what they want, and AI tools generate the code. This approach leans heavily on trust — developers often copy and paste AI output without double-checking everything.

In this environment, hallucinated packages become easy entry points for attackers, especially when developers skip manual review steps and rely solely on AI-generated suggestions.

How developers can protect themselves

To avoid falling victim to slopsquatting, experts recommend:

  • Manually verifying all package names before installation.
  • Using package security tools that scan dependencies for risks.
  • Checking for suspicious or brand-new libraries.
  • Avoiding copy-pasting install commands directly from AI suggestions.

Meanwhile, there is good news: some AI models are improving in self-policing. GPT-4 Turbo and DeepSeek, for instance, have shown they can detect and flag hallucinated packages in their own output with over 75% accuracy, according to early internal tests.

¿Quieres aplicar esto en tu empresa?

En TecnoArtesanos desarrollamos software, integramos IA y creamos experiencias digitales para negocios que quieren crecer.

Conversemos Nuestros servicios

¿Te gustó este artículo? Síguenos en Facebook para más contenido como este.

What you can read next

Amazon nos revela su estrategia para desafiar a Google y Microsoft: IA más barata y fiable a hiperescala
La IA está en camino de provocar un colapso bursátil aún mayor al de la burbuja puntocom
Target Max AI, la primera plataforma inteligente para PYMES en México que impulsará a 7,500 mujeres emprendedoras

Tecnología hecha a mano para tu negocio

Software, IA, sitios web y diseño. Hablemos de tu proyecto.

¿Hablamos? Síguenos en Facebook →

Recent Posts

  • ¿Quién responde por el algoritmo que recluta jóvenes para el crimen organizado?
  • InSpace: experiencias inmersivas en CDMX para eventos y lanzamientos
  • Dots vs. Muse: La batalla de los agentes personales de IA ha comenzado
  • Desconexión selectiva: la IA como el nuevo “Do Not Disturb”
  • Los padrinos de la IA advierten sobre una “explosión de inteligencia” que podría escapar al control humano

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • ¿Quién responde por el algoritmo que recluta jóvenes para el crimen organizado?

    Bajar o eliminar contenidos cuando las autorida...
  • InSpace: experiencias inmersivas en CDMX para eventos y lanzamientos

    A estas alturas es imposible pensar que la tecn...
  • Dots vs. Muse: La batalla de los agentes personales de IA ha comenzado

    Ayer pasé la mañana en el DevDay anual de OpenA...
  • Desconexión selectiva: la IA como el nuevo “Do Not Disturb”

    Piensa en el grupo de WhatsApp de la familia o ...
  • Los padrinos de la IA advierten sobre una “explosión de inteligencia” que podría escapar al control humano

    La humanidad podría estar a punto de experiment...

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized
TOP
TecnoArtesanos

Un estudio boutique que crea experiencias digitales: desarrollo de software, inteligencia artificial y soluciones en la nube, con el cuidado de la joyería fina.

¿Hablamos?

Servicios

  • Desarrollo de software
  • Integración de IA
  • Experiencias digitales
  • Redes sociales y diseño

TecnoArtesanos

  • Inicio
  • Portafolio
  • Nosotros
  • Blog

Contacto

  • +506 8730-7941
  • [email protected]
  • WhatsApp
  • Facebook
© 2026 TecnoArtesanos. Todos los derechos reservados. tecnoartesanos.com
TecnoArtesanos — Software a la medida, IA y sitios web para tu negocio. Conoce nuestros servicios →
✦ TecnoArtesanos

¿Te interesa llevar esto a tu negocio?

Escribimos sobre tecnología porque la construimos. Si tienes un proyecto en mente, conversemos: la primera llamada no tiene costo.

  • Desarrollo de software a la medida
  • Integración de inteligencia artificial
  • Sitios web y experiencias digitales
  • Redes sociales y diseño gráfico
¿Hablamos? Ver servicios

¿Prefieres WhatsApp? +506 8730-7941 · Síguenos en Facebook