AI Agent Recommends Malware Package, Highlighting Supply Chain Security Risks
An AI agent recommended a malicious software package to an engineer at Softjourn, a consulting and software development company. The AI suggested a plausible-sounding package for a common programming task, which, upon initial inspection, appeared legitimate. However, due to Softjourn's policy of verifying software recommendations from AI, the engineer checked the package's source code on GitHub. This review revealed that the package had very few downloads and had been created only a few days prior, raising suspicion. Sergiy Fitsak, managing director of Softjourn, explained that attackers are exploiting a phenomenon called 'slopsquatting,' where AI models sometimes 'hallucinate' non-existent but plausible package names. Attackers then register real packages under these invented names, hoping developers will install them without thorough verification, potentially leading to a supply chain compromise.