PulseAugur
EN
LIVE 03:54:15

LLMs invent non-existent code packages, creating slopsquatting risk

A study by VDB has revealed that large language models like Claude, GPT, and Gemini are generating non-existent package names for software development tasks. These fabricated names, which sound plausible and mimic real package naming conventions, pose a security risk known as 'slopsquatting.' Developers or automated agents following these LLM recommendations could inadvertently install malicious software if the invented package name is registered by an attacker. The research identified 83 such 'live targets' across various package registries, including npm, PyPI, and Go, highlighting a significant gap in LLM reliability for coding assistance. AI

IMPACT LLM-generated code suggestions may lead to security vulnerabilities through slopsquatting, requiring developers to verify all package recommendations.

RANK_REASON Research paper detailing a new vulnerability in LLM outputs related to code generation. [lever_c_demoted from research: ic=1 ai=1.0]

Read on dev.to — LLM tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

LLMs invent non-existent code packages, creating slopsquatting risk

COVERAGE [1]

  1. dev.to — LLM tag TIER_1 English(EN) · jj1423 ·

    Catching LLMs in a lie: packages that don't exist

    <p>Ask a language model which library to use and it answers with a list of names. Most are real. Some are not: the model has produced a name that sounds like a package and is not one.</p> <p>If someone registers that name first, the next developer — or the next coding agent — who…