AI incident
Hallucinated package names enable supply-chain attacks
Research · 2024
Organisation
Research
Year
2024
Failure mode
Hallucination → supply chain
Severity
major
Agentic
Yes — an AI system acting, not just advising
Source
Security research, 2024
What happened
Coding assistants suggest non-existent dependencies that attackers register ("slopsquatting").
What would have prevented it
Dependency allow-listing + SBOM + provenance checks
Requirements this maps to
Editorial cross-reference from our prevention note — it is not a finding that any law was breached.