AI Agent Recommends Malicious Package, Highlighting 'Slopsquatting' Threat to Software Supply Chain
An engineer at Softjourn, a consulting and software development company, nearly installed a malicious software package after an AI agent recommended it for a common task. The AI suggested a package with a legitimate-sounding name, formatted like a familiar library. However, Softjourn's policy of verifying AI recommendations led the engineer to inspect the package's source code on GitHub. The inspection revealed that the package had very few downloads and was recently created, raising suspicion. Sergiy Fitsak, managing director of Softjourn, explained that attackers are exploiting a phenomenon called 'slopsquatting,' where AI models 'hallucinate' plausible but non-existent package names. Attackers then register real packages under these invented names, anticipating that developers under pressure will install them without thorough verification. This incident underscores the critical need for human oversight in AI-assisted development to prevent supply chain compromises.