Фантазии LLM воплощаются в реальности — фальшивые опенсорсные библиотеки

LLM придумывает названия несуществующих библиотек и предлагает разработчикам-вайбкодерам пользоваться ими. Если есть спрос — возникнет и предложение. Вскоре эти библиотеки действительно появляются в реальности , но уже с вредоносным кодом.

https://habr.com/ru/companies/globalsign/articles/946872/

#llm #галлюцинации #slopsquatting #генерация_кода #фальшивки

Фантазии LLM воплощаются в реальности — фальшивые опенсорсные библиотеки

Использование галлюцинаций LLM для распространения вредоносного кода через опенсорсные репозитории В результате галлюцинаций чатботов в интернете возникли потоки трафика к несуществующим сайтам в...

Хабр

**Check this out: techno feudalism, chatons, slopsquatting and more (9. 8. 2025)**

(Self-sustainable organic farms (and self-hosted IT stuff) are a nice idea, but they are difficult to maintain in ‘island mode’. Are community owned shared data servers a solution?)

(Examples of community data servers in France)

(If you’re masochistic enough to join FOSS development and don’t know where to start, well, you can do it here. A list of open issues that are ‘easy’ solvable.)

(If you’re using LLM for code generation and then you install a non-existing library (that is hosted by the attacker), well, it’s your own fault.)

(You want to see what are your neighbours’ devices, like garage opener, up to? )

(You never know when you need retro-style display fonts)

(Windows 10 support is running out soon. Don’t buy a new computer, shoot yourself in the foot with a Linux! You will limp, but you’ll be free from mass-scale espionage.)

(Forget AI detector tools, hoomanz are also able to detect AI slop. Actually, the signs of slop are pretty straight forward. AI sounds like you listened to a hyped ultra positive grifter salesman/politician)

https://blog.rozman.info/check-this-out-techno-feudalism-chatons-slopsquatting-and-more-9-8-2025/

#endof10 #fonts #FOSS #homeassistant #LLM #slopsquatting

The Future is NOT Self-Hosted

In a world where corporations have detached buying from owning, one man attempts to do something radical: build his own cloud.

Drew Lyton

"#Slopsquatting is a type of #cybersquatting. It is the practice of registering a non-existent software package name that a large language model (#LLM) may hallucinate in its output, whereby someone unknowingly may copy-paste and install the #software package without realizing it is #fake."

https://en.wikipedia.org/wiki/Slopsquatting

Slopsquatting - Wikipedia

Ok, ich lass mich mal zu einer #Prophezeiung hinreißen.

#Slopsquatting ist ja ein alter Hut.

Aber was haltet ihr von #Slopswatting? Also das gezielte Platzieren von Falschinfos im Internet, sodass AI-aided Policing-Systeme kunkludieren, dass eine bestimmte Person ein ganz gefährlicher Gefährder ist, den man mal hochnehmen sollte?

#LLM can't stop making up software dependencies and sabotaging everything
Hallucinated package names fuel '#slopsquatting'
As #AI #coding assistants invent nonexistent software libraries to download and use, enterprising attackers create and upload libraries with those names—laced with #malware, of course.
https://www.theregister.com/2025/04/12/ai_code_suggestions_sabotage_supply_chain/
LLMs can't stop making up software dependencies and sabotaging everything

: Hallucinated package names fuel 'slopsquatting'

The Register

📢 AI coding tools are creating silent vulnerabilities through "slopsquatting"—where attackers register package names hallucinated by AI.
This attack vector “exploits vibecoding" (using AI without review) and specifically targets less technical developers. 

#AISecurityRisks #Slopsquatting #VibeCoding #SecureCoding #CyberSecurity

https://www.lotharschulz.info/2025/05/12/the-hidden-poison-in-ai-generated-code-how-vibecoding-enables-slopsquatting-attacks/

The hidden poison in AI-generated code: How vibecoding enables slopsquatting attacks – Lothar Schulz

Curious about the buzzwords shaping the future of AI?

From vibe coding to ‘slopsquatting’, we're breaking down what these mean and their impact on tech and cybersecurity. Check out the latest @sharedsecurity episode for insights!

Watch on YouTube:
https://youtu.be/vi7a9ciHPjg

Listen and subscribe to the podcast!
https://sharedsecurity.net/subscribe

https://sharedsecurity.net/2025/05/05/what-vibe-coding-mcp-and-slopsquatting-reveal-about-the-future-of-ai-development/

#cybersecurity #ai #podcast #vibecoding #slopsquatting #mcp

Welcome to the AI Development Era: Vibe Coding, MCP, and Slopsquatting Explained #podcast

YouTube

Researchers have uncovered a new supply chain attack called #Slopsquatting where threat actors exploit hallucinated, non-existent package names generated by #AI coding tools like #GPT4 and #CodeLlama

These believable yet fake packages (amounting to 19.7% or 205,000 packages), recommended in test samples were found to be fakes., can be registered by attackers to distribute malicious code.

Open-source models -- like #DeepSeek and #WizardCoder -- hallucinated more frequently, at 21.7% on average, compared to the commercial ones (5.2%) like GPT 4.

We Have a Package for You! A Comprehensive Analysis of Package Hallucinations
by Code Generating LLMs (PDF) https://arxiv.org/pdf/2406.10279

Ich lese von #vibecoding und #Slopsquatting und und stelle mir vor, wie eine Unzahl von Teens und Erwachsenen sich völlig arglos malware installiert, weil "coder" der KI blind vertrauen.

Naja, zumindest werden wir mit Jakkaru genug zu tun haben... 🤷‍♀️