{"data":{"id":"6043ae3e-ce10-48d4-b88b-5eb2c1559026","title":"Top AIs invent same fake PyPl and npm package names","summary":"Multiple AI coding tools consistently hallucinate (generate false information about) the same fake software package names, creating a security risk called slopsquatting, where attackers register these nonexistent packages as malicious software to trick developers into using them. Researcher Aleksandr Churilov found that five different AI models generated 127 identical fake package names, with 53 of those names still available for malicious registration as of April. While no active attacks using these fake packages have been detected yet, the consistent hallucinations across different AI systems pose an ongoing threat to enterprise developers.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://www.csoonline.com/article/4201164/top-ais-invent-same-fake-pypl-and-npm-package-names-2.html","publishedAt":"2026-07-24T10:39:51.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI","Google"],"affectedVendorsRaw":["Claude Sonnet","Claude Haiku","GPT-5.4-mini","Gemini 2.5 Pro","DeepSeek"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-24T10:39:51.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}