AI-hallucinated code dependencies become new supply chain risk

AI-hallucinated code dependencies become new supply chain risk

A new class of supply chain attacks named ‘slopsquatting’ has emerged from the increased use of generative AI tools for coding and the model’s tendency to “hallucinate” non-existent package names.

The term slopsquatting was coined by security researcher Seth Larson as a spin on typosquatting, an attack method that tricks developers into installing malicious packages by using names that closely resemble popular libraries.

Unlike typosquatting, slopsquatting doesn’t rely on…

Article Source
https://www.bleepingcomputer.com/news/security/ai-hallucinated-code-dependencies-become-new-supply-chain-risk/

More From Author

Boost for Apple and Nvidia as Trump exempts smartphones, computers, and electronic items from tariffs; will stocks rise following the move?

Boost for Apple and Nvidia as Trump exempts smartphones, computers, and electronic items from tariffs; will stocks rise following the move?

Apple, Nvidia, and Microsoft can 'breathe a huge sigh of relief' after Trump's China tariff exemptions – MSN

Listen to the Podcast Overview

Watch the Keynote