{"id":8868,"date":"2026-07-24T10:39:51","date_gmt":"2026-07-24T10:39:51","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8868"},"modified":"2026-07-24T10:39:51","modified_gmt":"2026-07-24T10:39:51","slug":"top-ais-invent-same-fake-pypl-and-npm-package-names","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8868","title":{"rendered":"Top AIs invent same fake PyPl and npm package names"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response.<\/p>\n<p class=\"wp-block-paragraph\">The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different LLMs.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.csoonline.com\/article\/3961304\/ai-hallucinations-lead-to-new-cyber-threat-slopsquatting.html\">Slopsquatting is a relatively new form of malware attack<\/a> that involves the creation of malicious packages in response to the hallucinations of AI coding tools, causing the malicious packages to be incorporated into legitimate applications.<\/p>\n<p class=\"wp-block-paragraph\">Churilov set out his findings in a research paper, <a href=\"https:\/\/arxiv.org\/abs\/2605.17062\" target=\"_blank\" rel=\"noopener\">The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort<\/a>, which is yet to be peer-reviewed. He found 127 hallucinated package names were shared across Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2.<\/p>\n<p class=\"wp-block-paragraph\">\u00a0As of April this year, 53 of those names \u2014 41 on the PyPI software repository and 12 on npm \u2014are still available for registration.<\/p>\n<p class=\"wp-block-paragraph\">According to the study, there are two reasons for this amount of conformity in the output of the models. First, models may learn the same incorrect package references from shared public training material, such as tutorials and documentation.<\/p>\n<p class=\"wp-block-paragraph\">Second, they may independently extrapolate plausible names from ecosystem conventions. In this way, they could produce names that look correct, even if they don\u2019t actually exist.<\/p>\n<p class=\"wp-block-paragraph\">While Churilov\u2019s research will worry CISOs and security-conscious developers, there is some relief. The research has not yet found any evidence that any of the remaining 53 names have been registered maliciously, nor used in an attack.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <a href=\"https:\/\/www.infoworld.com\/article\/4200884\/top-ais-invent-same-fake-pypl-and-npm-package-names.html\">InfoWorld<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8869,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8868","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8868"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8868"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8868\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8869"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}