Slopsquatting, explained
Slopsquatting is typosquatting for the AI era. Instead of guessing typos, attackers register the package names that code models invent, then wait for someone to install them.
How it works
- A coding assistant writes
import { x } from "some-plausible-name", and that package doesn't exist. - Models repeat the same invented names across many users and sessions, so the names are predictable.
- An attacker publishes a package with that name on npm or PyPI, with an install script that steals credentials.
- A developer sees "module not found", runs
npm install some-plausible-name, and the payload runs.
Academic work on package hallucination has measured how often popular models suggest non-existent packages, and found many of those names recur, which is what makes the attack practical. Security researchers coined the term in 2025.
How to protect a repo
- Check imports against the manifest in CI. Any import that isn't declared fails the PR before anyone is tempted to "fix" it by installing. SlopScore for Code does this as an error-level rule.
- Review new dependencies like code. Age, weekly downloads, repository link, maintainers, install scripts.
- Disable install scripts by default where you can (
npm config set ignore-scripts true, then allow-list). - Pin dependencies and review lockfile changes.
Check a PR now
Paste a public GitHub PR on the home page. Undeclared imports show up as errors, with the line.