Free Consultation
Home Incident Radar Hallucinated package names enable supply-chain attacks
AI incident

Hallucinated package names enable supply-chain attacks

Research · 2024

Organisation
Research
Year
2024
Failure mode
Hallucination → supply chain
Severity
major
Agentic
Yes — an AI system acting, not just advising
Source
Security research, 2024

What happened

Coding assistants suggest non-existent dependencies that attackers register ("slopsquatting").

What would have prevented it

Dependency allow-listing + SBOM + provenance checks

Requirements this maps to

Editorial cross-reference from our prevention note — it is not a finding that any law was breached.