Togoder security

Glossary

What is slopsquatting?

Also called: package hallucination, AI package hallucinationUpdated

Definition

Slopsquatting is registering package names that AI models hallucinate, so that when a coding assistant (or a developer copying its answer) runs the install command, the attacker's package is what gets installed.

How slopsquatting works

Large language models sometimes recommend packages that do not exist: a plausible name like flask-auth-helpers or react-native-secure-store-utils. The name follows the ecosystem's conventions, so it looks right. If nobody owns it, an attacker can publish it.

The term was coined in 2025 (a play on typosquatting and AI "slop"). It matters because hallucinations repeat: academic research on code-generating models found that roughly one in five recommended packages did not exist, and many of the invented names came back again and again across runs. A repeated name is a predictable target.

The risk is highest for agents that install dependencies on their own. A human might notice an unfamiliar name; an agent running npm install or pip install in a loop usually will not.

How to defend against slopsquatting

  • Treat every dependency an AI suggests as unverified. Check that it exists, who publishes it, how old it is and how many people download it.
  • Be suspicious of packages that are days old, have no repository, or have a single version.
  • Give coding agents a vetting step before installs. Togoder Security exposes an x402 API agents can pay per call to scan a package's source before installing it.
  • Run installs with lifecycle scripts disabled, so a squatted name cannot execute code at install time.

Frequently asked questions

What is the difference between typosquatting and slopsquatting?

Typosquatting bets on humans mistyping a real package name. Slopsquatting bets on AI models inventing a package name that does not exist yet, which the attacker then registers.

Which ecosystems are affected?

Any registry where names are first come, first served, which includes npm, PyPI, crates.io and RubyGems. npm and PyPI see the most activity because AI assistants recommend them most.