STUPID-2026-0033
Slopsquatting: LLMs hallucinate package names attackers pre-register (react-codeshift, unused-imports)
Instruction given
Recommend or install packages while generating code.
Expected behavior
Only reference packages that actually exist and are verified before installation.
Actual behavior
Across 576,000 code samples from 16 LLMs, roughly 19.7% of recommended packages did not exist. 43% of hallucinated names recurred on every one of ten identical runs — predictable enough that attackers pre-register the names as malware.
Damage
Attackers registered hallucinated names such as react-codeshift (a conflation of jscodeshift and react-codemod) and unused-imports (instead of eslint-plugin-unused-imports). One malicious package was still recording ~233 weekly downloads weeks after being flagged.
Classification
- Agent
- Multiple LLMs
- Failure mode
- Hallucination
- Root cause
- Training Data Gap
- Domain
- Backend
- Language
- Javascript
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.