惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
Hacker News: Ask HN
Hacker News: Ask HN
T
Threatpost
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
P
Palo Alto Networks Blog
S
SegmentFault 最新的问题
月光博客
月光博客
Latest news
Latest news
博客园 - Franky
T
Threat Research - Cisco Blogs
有赞技术团队
有赞技术团队
博客园_首页
T
The Exploit Database - CXSecurity.com
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
爱范儿
爱范儿
Security Latest
Security Latest
Scott Helme
Scott Helme
博客园 - 聂微东
T
Tor Project blog
美团技术团队
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
Jina AI
Jina AI
Vercel News
Vercel News
小众软件
小众软件
T
Tenable Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Forbes - Security
Forbes - Security
aimingoo的专栏
aimingoo的专栏
O
OpenAI News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Last Watchdog
The Last Watchdog
Cloudbric
Cloudbric
AI
AI

Socket

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ... Socket for Linear Is Now Available - Socket US Government Forces Anthropic to Pull Claude Fable Days After Launch 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic Andrew Becherer Joins Socket as Chief Information Security Officer Socket Partners with Replit to Block Malicious Packages in AI-Powered Development npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems pnpm 11.5 Adds Support for Recognizing npm Staged Publishes pnpm 11.5 Adds Support for Recognizing npm Staged Publishes Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Famous Chollima Targets PHP Developers Through Compromised Packagist Package Famous Chollima Targets PHP Developers Through Compromised Packagist Package Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io Laravel Lang Compromised with RCE Backdoor Across 700+ Versions Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects AI Has Taken Over Open Source npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor Active Supply Chain Attack Compromises @antv Packages on npm Popular node-ipc npm Package Infected with Credential Stealer TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks Packagist Urges Immediate Composer Update After GitHub Actions Token Leak GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack fsnotify Maintainer Dispute Sparks Supply Chain Concerns Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies PyPI Fixes High-Severity Access Control Issues Found in Security Audit Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack lightning PyPI Package Compromised in Supply Chain Attack Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables SAP CAP npm Packages Hit by Supply Chain Attack Socket Has Acquired Secure Annex 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations Introducing Reachability for PHP Introducing Data Exports Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions Introducing Organization Notifications in Socket Introducing Reports: An Extensible Reporting Framework for Socket Data Socket for Jira Is Now Available Socket Named Top Sales Organization by RepVue NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets Socket Selected for OpenAI's Cybersecurity Grant Program Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure Node.js Drops Bug Bounty Rewards After Funding Dries Up The Hidden Blast Radius of the Axios Compromise
New Study Identifies 53 Slopsquatting Targets Across 5 Front...
Sarah Gooding · 2026-07-22 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

A new independent research preprint examining nearly 200,000 code-generation responses found that five frontier large language models continue to invent package names that do not exist on PyPI or npm.

The models’ overall package-hallucination rates were much closer than those measured in earlier research, ranging from 4.62% to 6.10%. The study also identified package names generated by every model in the test group.

The initial analysis found 127 names shared across Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2. After review by PyPI Security and Socket, researchers determined that 53 of those names, 41 on PyPI and 12 on npm, were still available for registration as of April 2026.

An attacker could publish malware under one of these names and wait for an AI coding tool to recommend it to a developer. This technique, known as slopsquatting, exploits package names that AI models repeatedly invent. Because every model in the study generated the same names, one malicious registration could potentially target users across several model providers.

The findings appear in “The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort,” by independent researcher Aleksandr Churilov. His study has been posted to arXiv but has not been peer-reviewed.

The research identifies potential slopsquatting targets, not an active attack. There is no evidence in the study that any of the 53 names have been registered maliciously or used to compromise developers.

Frontier models narrowed the gap without eliminating hallucinations#

The study replicates the methodology of research presented at USENIX Security 2025, which tested 16 code-generating LLMs and reported average package-hallucination rates of 5.2% among commercial models and 21.7% among open-source models.

Churilov tested five newer models against the same prompt corpus, generating 199,845 responses between April 22 and April 28, 2026. The prompts included approximately 20,000 programming questions collected from Stack Overflow and approximately 20,000 synthetically generated questions, divided between Python and JavaScript.

The measured rates were:

Model Python JavaScript Overall
Claude Haiku 4.5 5.49% 2.76% 4.62%
Claude Sonnet 4.6 6.63% 2.62% 5.41%
Gemini 2.5 Pro 6.75% 3.61% 5.80%
DeepSeek V3.2 6.69% 3.78% 5.89%
GPT-5.4-mini 7.27% 3.14% 6.10%

The spread between the lowest and highest rates narrowed from 16.5 percentage points in the earlier model cohort to 1.48 percentage points. However, none of the five models improved upon the earlier study’s lowest individual result of approximately 3.6% for GPT-4 Turbo.

GPT-5.4-mini’s result also carries an important qualification. It was tested at minimal reasoning effort and refused 32.14% of prompts, substantially more than the other models. Its hallucination rate was calculated only from compliant, parseable responses, which may not represent the full prompt distribution.

Python package hallucinations exceeded JavaScript hallucinations across all five models, reversing the earlier study’s finding that JavaScript produced more. The author suggests that newer models may have absorbed npm’s naming conventions more effectively than Python’s mix of import names, distribution names, and naming formats.

The researchers compared the unique package names generated by each model and found an initial intersection of 127 names: 109 associated with PyPI and 18 with npm.

These were not merely similar names. Each candidate appeared in output from all five tested models.

Each shared name gives an attacker a single registration target that could surface in output from models offered by Anthropic, OpenAI, Google, and DeepSeek.

The study proposes two possible explanations for this convergence. Models may learn the same incorrect package references from shared public training material, such as tutorials and documentation. They may also independently extrapolate plausible names from ecosystem conventions, producing names that look correct despite not corresponding to standalone packages.

DeepSeek V3.2 and GPT-5.4-mini had the greatest overall overlap between their hallucinated-name sets, with a Jaccard similarity score of 0.343. The paper says this could indicate common training-data patterns or convergent generation behavior, but the results do not establish a training-data relationship between the providers.

Socket’s review removed six npm false positives#

Churilov contacted Socket on April 29 after attempts to send the npm findings through the registry’s published security channels were unsuccessful. Socket reviewed all 18 npm candidates against the registry and relevant framework module systems.

That review found that the four highest-volume npm entries were valid Ember.js imports:

  • @ember/service
  • @ember/object
  • @ember/routing
  • @ember/controller

These modules resolve through ember-source rather than existing as standalone npm packages. An LLM generating an import such as @ember/service is producing valid Ember code, even though a direct npm registry lookup for that package name returns a 404.

The review also found that ssh-keys was an existing npm package and that metro-evaluator was already represented by a security-hold package.

These six names were removed from the exploitable npm set. The remaining 12 appeared in output from every tested model and had no corresponding package, framework resolver, or existing security hold when reviewed. Public examples from the paper include css-color-stop, dns-sd, and dom-ains.

PyPI Security separately reviewed the 109 Python candidates. Its prohibited-name list and normalization protections prevented registration of 68, leaving 41 available.

Together, the reviews reduced the original 127-name intersection to 53 registrable candidates.

Registry lookups alone can misclassify valid imports#

Socket’s review identified a limitation in the study’s inherited extraction pipeline: absence from a package registry does not always mean that an import is hallucinated.

Frameworks can provide virtual modules, bundled subpackages, aliases, and other import paths that are valid in source code but have no standalone registry entry. Regex-based extraction followed by a registry existence check can therefore classify correct code as a hallucination.

Churilov incorporated Socket’s findings into version 2 of the paper, documenting framework-provided virtual namespaces as a false-positive class and distinguishing the raw 127-name intersection from the 53 names that remained registrable.

The final figure is still a point-in-time estimate. PyPI and npm protections change, names may subsequently be registered, and the two ecosystems were evaluated differently: PyPI Security applied internal automated defenses, while Socket manually investigated the npm candidates.

The results do not represent every AI coding workflow#

The study tested one response from each model for each prompt rather than measuring package suggestions inside complete coding-agent workflows. Agents that retrieve current registry data before suggesting or installing dependencies may avoid some of these errors.

The measurements also cover specific model snapshots and settings from one week in April. Hosted models can change without retaining the same public identifier, and the older prompt corpus may have appeared in newer models’ training data.

The study also relied on a regex-based extractor inherited from the earlier research. Socket’s review of the Ember.js imports demonstrates how that method can mistake valid framework modules for nonexistent packages without additional ecosystem-specific validation.

Even with those limitations, the shared names demonstrate that package hallucination remains relevant to the software supply chain. Developers should treat dependencies introduced by AI-generated code as unverified until the package name, publisher, history, and relationship to the intended project have been confirmed.

Lockfiles and version pinning can prevent later dependency drift, but they do not make an unfamiliar package safe when it first enters a project. New AI-suggested dependencies should receive the same review as dependencies proposed by an unknown external contributor.