A new study has re-evaluated the tendency of large language models to hallucinate non-existent package names, a vulnerability known as slopsquatting. Researchers tested five frontier code-capable LLMs released between October 2025 and March 2026, finding overall hallucination rates between 4.62% and 6.10%. While this range is significantly smaller than previous findings, the threat persists, with 53 identical, model-agnostic hallucinated package names remaining registrable on PyPI and npm despite existing defenses. The study also noted an asymmetry in Python versus JavaScript hallucinations and a similarity between DeepSeek V3.2 and GPT-5.4-mini, suggesting shared training data. AI
IMPACT Identifies a persistent supply-chain attack surface across multiple frontier LLMs, necessitating improved defenses against package name hallucinations.
RANK_REASON The cluster contains an academic paper detailing research findings on LLM behavior. [lever_c_demoted from research: ic=1 ai=1.0]
- Anthropic
- Claude Haiku 4.5
- Claude Sonnet 4.6
- DeepSeek V3.2
- Gemini 2.5 Pro
- GPT 5.4 Mini
- Python Package Index
- Spracklen et al.
- USENIX Security '25
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →