Slopsquatting uses AI‑hallucinated names to threaten open‑source projects
Slopsquatting is the name for a new software supply chain attack built directly on LLM package hallucinations. The source frames it as a category shift from typosquatting: instead of betting on developer typos, attackers register the non-existent package names that AI coding assistants confidently invent, then upload malware under