Skip to main content
All terms
Safety & Alignment

Slopsquatting

Registering fake software packages whose names AI coding tools tend to invent.

Definition

Slopsquatting is a software supply-chain attack that exploits AI coding tools inventing package names that do not exist. An attacker registers that made-up name and publishes malicious code under it, so a developer who trusts the AI's suggestion installs the attacker's package by mistake.