A study by VDB has revealed that large language models like Claude, GPT, and Gemini are generating non-existent package names for software development tasks. These fabricated names, which sound plausible and mimic real package naming conventions, pose a security risk known as 'slopsquatting.' Developers or automated agents following these LLM recommendations could inadvertently install malicious software if the invented package name is registered by an attacker. The research identified 83 such 'live targets' across various package registries, including npm, PyPI, and Go, highlighting a significant gap in LLM reliability for coding assistance. AI
IMPACT LLM-generated code suggestions may lead to security vulnerabilities through slopsquatting, requiring developers to verify all package recommendations.
RANK_REASON Research paper detailing a new vulnerability in LLM outputs related to code generation. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →