Hallucinated Dependencies and Slopsquatting
Why a code-generating model invents package names that do not exist, why it invents the same ones repeatedly, and how that repeatability turns a model error into a pre-registerable attack surface that lockfiles and signatures cannot see.
Every supply chain control built since 2016 assumes the dependency already exists. Lockfiles pin a version of something on a registry. Integrity hashes bind a name to bytes. Attestations bind bytes to a publisher. All of it starts from a name that entered the manifest somehow, and none of it asks where that name came from. Code-generating models introduced a new answer to that question: the model made it up.
The scale is measured, not anecdotal. Spracklen and colleagues generated 576,000 code samples from 16 code-generating models across Python and JavaScript, extracted the 2.23 million package references inside them, and found that 440,445 references, 19.7 percent, pointed at packages that did not exist. Those resolved to 205,474 distinct invented names (Spracklen et al., 2025, We Have a Package for You!, USENIX Security 25). Open-weight models hallucinated 21.7 percent of the packages they recommended; commercial models, 5.2 percent.
An invented name is normally harmless. pip install fails, the developer notices, the name is corrected. It stops being harmless the moment somebody registers the name first.
Why the inventions repeat
A one-off error is a nuisance. A reproducible error is a target list, and this is the finding that makes the attack economic. When the same prompt that produced a hallucination was re-issued ten times, 43 percent of hallucinated packages appeared in all ten responses and 58 percent appeared more than once; only 39 percent never came back (Spracklen et al., 2025).
That stability follows from how the names are produced. The largest category, 38 percent, is conflation: the model fuses two real package names, or splices a real project name onto a real naming convention, so the output sits exactly where a plausible package would sit in token space. huggingface-cli is the canonical example, a name that reads correctly to any Python developer and that the real project never used. Sampling temperature moves the rate; it does not move the identity of the attractor, because the attractor is where probability mass already is.
Seth Larson of the Python Software Foundation named the resulting attack slopsquatting in April 2025: register the names the models keep inventing and wait. Unlike typosquatting, no user error is required. The victim types exactly what they were told to type.
Newer models shrink the range, not the surface
The obvious hope is that better models end this. They compress it. A 2026 re-evaluation put five frontier code models released between October 2025 and March 2026 through 199,845 paired Python and JavaScript prompts and measured hallucination rates between 4.62 and 6.10 percent, an order-of-magnitude narrowing of the spread between best and worst but not a retirement of the problem. More usefully, it isolated 127 package names that all five models invent identically, of which 53 remained registrable by an attacker after each registry's existing defences (2026, The Range Shrinks, the Threat Remains, arXiv:2605.17062).
A model-agnostic name is the worst case for a defender. Switching vendors, running an ensemble, or asking two models and comparing does not help when every model converges on the same invented string.
The proof of concept that landed
Bar Lanyado registered huggingface-cli on PyPI in December 2023 as an empty proof of concept after watching models recommend it repeatedly. Within three months it had more than 15,000 downloads, and Alibaba's GraphTranslator repository was instructing users to install it in its README (The Register, 2024). Nobody was phished and nothing was typo'd. A hallucination propagated into human-written documentation, where it became an ordinary, durable instruction.
When it breaks
The lockfile arrives too late. Pinning and hash-checking protect a dependency after it is adopted. Slopsquatting attacks adoption itself: the first pip install writes the attacker's package into the lockfile, and every subsequent build reproduces the compromise faithfully. Reproducibility is not integrity.
Attestation proves the wrong property. PEP 740 attestations bind a distribution to the identity that published it and to the build that produced it, and the PyPI documentation is explicit that this is integrity rather than trustworthiness (PyPI, 2024, PyPI now supports digital attestations). An attacker publishing a slopsquatted package through GitHub Actions gets a valid attestation. The package is exactly what its publisher intended it to be; the publisher is the problem.
Blocklists cannot be pre-computed at useful coverage. 205,474 unique names from one study is a floor, not a ceiling, and the set shifts with every model release, every prompt phrasing and every new library that gives conflation fresh material. Registry-side name reservation handles the few hundred names research has disclosed, not the long tail.
Self-detection is real but partial. The same study found models can flag a substantial share of their own hallucinated names when asked directly, and that retrieval grounding and fine-tuning both reduce the rate, with fine-tuning giving the largest reduction. None of these drive it to zero, and a verification step that runs inside the same model that produced the error inherits its blind spots.
Agents close the loop that used to contain the damage. A human reading ModuleNotFoundError is a checkpoint. An autonomous coding agent that sees the same error and runs pip install to clear it has converted the checkpoint into an installation, at machine speed, with no one watching.
References and further reading
Every source this page cites, in the order it cites them. All of them open in a new tab.
- Spracklen et al., 2025, We Have a Package for You!, USENIX Security 25 usenix.org
- Spracklen et al., 2025 github.com
- 2026, The Range Shrinks, the Threat Remains, arXiv:2605.17062 arxiv.org
- The Register, 2024 theregister.com
- PyPI, 2024, PyPI now supports digital attestations blog.pypi.org
6 flashcards for this concept
Click a card to reveal the answer.