{"id":796,"date":"2025-04-16T19:09:46","date_gmt":"2025-04-16T19:09:46","guid":{"rendered":"https:\/\/www.techrepublic.com\/?p=4302149"},"modified":"2025-04-16T19:09:46","modified_gmt":"2025-04-16T19:09:46","slug":"developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks","status":"publish","type":"post","link":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/","title":{"rendered":"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4302150 aligncenter\" src=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280.jpg\" alt=\"Zoomed in monitor with programming.\" width=\"1280\" height=\"853\" srcset=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280.jpg 1280w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-300x200.jpg 300w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-1024x682.jpg 1024w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-768x512.jpg 768w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-50x33.jpg 50w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-770x513.jpg 770w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-370x247.jpg 370w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-270x180.jpg 270w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-740x493.jpg 740w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-540x360.jpg 540w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-1110x740.jpg 1110w, https:\/\/assets.techrepublic.com\/uploads\/2025\/04\/code-820275_1280-810x540.jpg 810w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\"><\/p>\n<p>Security researchers and developers are raising alarms over \u201cslopsquatting,\u201d a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like GitHub Copilot, ChatGPT, and DeepSeek, attackers are exploiting AI\u2019s tendency to invent software packages, tricking users into downloading malicious content.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_is_slopsquatting\"><\/span>What is slopsquatting?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The term slopsquatting was originally coined by Seth Larson, a developer with the Python Software Foundation, and later popularized by tech security researcher Andrew Nesbitt. It refers to cases where attackers register software packages that don\u2019t actually exist but are mistakenly suggested by AI tools; once live, these fake packages can contain harmful code.<\/p>\n<p>If a developer installs one of these without verifying it \u2014 simply trusting the AI \u2014 they may unknowingly introduce malicious code into their project, giving hackers backdoor access to sensitive environments.<\/p>\n<p>Unlike typosquatting, where malicious actors count on human spelling mistakes, slopsquatting relies entirely on AI\u2019s flaws and developers misplaced trust in automated suggestions.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"AI-hallucinated_software_packages_are_on_the_rise\"><\/span>AI-hallucinated software packages are on the rise<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This issue is more than theoretical. A recent joint study by researchers at the University of Texas at San Antonio, Virginia Tech, and the University of Oklahoma analyzed more than 576,000 <a href=\"https:\/\/www.techrepublic.com\/article\/ai-generated-code-outages\/\">AI-generated code<\/a> samples from 16 large language models (LLMs). They found that nearly 1 in 5 packages suggested by AI didn\u2019t exist.<\/p>\n<p>\u201cThe average percentage of hallucinated packages is at least 5.2% for commercial models and 21.7% for open-source models, including a staggering 205,474 unique examples of hallucinated package names, further underscoring the severity and pervasiveness of this threat,\u201d <a href=\"https:\/\/arxiv.org\/abs\/2406.10279\" target=\"_blank\" rel=\"noopener\">the study revealed<\/a>.<\/p>\n<p>Even more concerning, these hallucinated names weren\u2019t random. In multiple runs using the same prompts, 43% of hallucinated packages consistently reappeared, showing how predictable these hallucinations can be. As explained by the security firm Socket, this consistency gives attackers a roadmap \u2014 they can monitor AI behavior, identify repeat suggestions, and register those package names before anyone else does.<\/p>\n<p>The study also noted differences across models: CodeLlama 7B and 34B had the highest hallucination rates of over 30%; GPT-4 Turbo had the lowest rate at 3.59%.<\/p>\n<aside class=\"pinbox right\">\n<h3 class=\"heading\">Must-read security coverage<\/h3>\n<\/aside>\n<h2><span class=\"ez-toc-section\" id=\"How_vibe_coding_might_increase_this_security_risk\"><\/span>How vibe coding might increase this security risk<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A growing trend called vibe coding, a term coined by AI researcher Andrej Karpathy, may worsen the issue. It refers to a workflow where developers describe what they want, and AI tools generate the code. This approach leans heavily on trust \u2014 developers often copy and paste AI output without double-checking everything.<\/p>\n<p>In this environment, hallucinated packages become easy entry points for attackers, especially when developers skip manual review steps and rely solely on AI-generated suggestions.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_developers_can_protect_themselves\"><\/span>How developers can protect themselves<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To avoid falling victim to slopsquatting, experts recommend:<\/p>\n<ul>\n<li>Manually verifying all package names before installation.<\/li>\n<li>Using package <a href=\"https:\/\/www.techrepublic.com\/article\/best-ai-security-tools\/\">security tools<\/a> that scan dependencies for risks.<\/li>\n<li>Checking for suspicious or brand-new libraries.<\/li>\n<li>Avoiding copy-pasting install commands directly from AI suggestions.<\/li>\n<\/ul>\n<p>Meanwhile, there is good news: some <a href=\"https:\/\/www.techrepublic.com\/article\/tech-trends-2024\/\">AI models<\/a> are improving in self-policing. GPT-4 Turbo and DeepSeek, for instance, have shown they can detect and flag hallucinated packages in their own output with over 75% accuracy, according to early internal tests.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers and developers are raising alarms over \u201cslopsquatting,\u201d a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like GitHub Copilot, ChatGPT, and DeepSeek, attackers are exploiting AI\u2019s tendency to invent software packages, tricking users into downloading malicious content. What is slopsquatting? [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":797,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-796","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog\" \/>\n<meta property=\"og:description\" content=\"Security researchers and developers are raising alarms over \u201cslopsquatting,\u201d a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like GitHub Copilot, ChatGPT, and DeepSeek, attackers are exploiting AI\u2019s tendency to invent software packages, tricking users into downloading malicious content. What is slopsquatting? [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"TecnoArtesanos Tech Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-16T19:09:46+00:00\" \/>\n<meta name=\"author\" content=\"Sergio Morales\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sergio Morales\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/\",\"name\":\"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg\",\"datePublished\":\"2025-04-16T19:09:46+00:00\",\"author\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg\",\"contentUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.tecnoartesanos.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/\",\"name\":\"TecnoArtesanos Tech Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\",\"name\":\"Sergio Morales\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"caption\":\"Sergio Morales\"},\"sameAs\":[\"https:\/\/sergiomorales.space\"],\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog","og_description":"Security researchers and developers are raising alarms over \u201cslopsquatting,\u201d a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like GitHub Copilot, ChatGPT, and DeepSeek, attackers are exploiting AI\u2019s tendency to invent software packages, tricking users into downloading malicious content. What is slopsquatting? [&hellip;]","og_url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/","og_site_name":"TecnoArtesanos Tech Blog","article_published_time":"2025-04-16T19:09:46+00:00","author":"Sergio Morales","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sergio Morales","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/","url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/","name":"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks - TecnoArtesanos Tech Blog","isPartOf":{"@id":"https:\/\/blog.tecnoartesanos.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage"},"image":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg","datePublished":"2025-04-16T19:09:46+00:00","author":{"@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807"},"breadcrumb":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#primaryimage","url":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg","contentUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/04\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/04\/16\/developers-beware-slopsquatting-vibe-coding-can-increase-risk-of-ai-powered-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.tecnoartesanos.com\/"},{"@type":"ListItem","position":2,"name":"Developers Beware: Slopsquatting &amp; Vibe Coding Can Increase Risk of AI-Powered Attacks"}]},{"@type":"WebSite","@id":"https:\/\/blog.tecnoartesanos.com\/#website","url":"https:\/\/blog.tecnoartesanos.com\/","name":"TecnoArtesanos Tech Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807","name":"Sergio Morales","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","caption":"Sergio Morales"},"sameAs":["https:\/\/sergiomorales.space"],"url":"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/comments?post=796"}],"version-history":[{"count":0,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/796\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media\/797"}],"wp:attachment":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media?parent=796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/categories?post=796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/tags?post=796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}