SlopScore for Code

Slopsquatting, explained

Slopsquatting is typosquatting for the AI era. Instead of guessing typos, attackers register the package names that code models invent, then wait for someone to install them.

How it works

  1. A coding assistant writes import { x } from "some-plausible-name", and that package doesn't exist.
  2. Models repeat the same invented names across many users and sessions, so the names are predictable.
  3. An attacker publishes a package with that name on npm or PyPI, with an install script that steals credentials.
  4. A developer sees "module not found", runs npm install some-plausible-name, and the payload runs.

Academic work on package hallucination has measured how often popular models suggest non-existent packages, and found many of those names recur, which is what makes the attack practical. Security researchers coined the term in 2025.

How to protect a repo

Check a PR now

Paste a public GitHub PR on the home page. Undeclared imports show up as errors, with the line.

More