네임스페이스 메뚜기 떼: AI가 잠식한 패키지 저장소의 위기

최근 3년간 RubyGems, npm 등 주요 저장소에 200만 개의 신규 패키지가 등록되었으나, 대다수는 AI가 생성한 저품질의 중복 패키지이거나 이름 선점용이다.

🔗 원문 보기

네임스페이스 메뚜기 떼: AI가 잠식한 패키지 저장소의 위기

최근 3년간 RubyGems, npm 등 주요 저장소에 200만 개의 신규 패키지가 등록되었으나, 대다수는 AI가 생성한 저품질의 중복 패키지이거나 이름 선점용이다.

Ruby-News | 루비 AI 뉴스
This article is adapted from The Confidence Trap, part of the "2026 Supply Chain Reckoning" series on my No Regressions newsletter. Your boss calls you on a Friday afternoon. He's read all the available data, he tells you with absolute confidence, and he's decided that migrating from Spring Boot...
#ai #codegeneration #copilot #hallucination #Java #LLM #maven #slopsquatting #softwaresecurity #supplychainsecurity
https://foojay.io/today/why-java-developers-over-trust-ai-dependency-suggestions/
Why Java Developers Over-Trust AI-Generated Code

AI coding tools sound confident even when they're wrong. Here's the psychology behind why Java developers accept bad suggestions — and habits that help.

foojay
#AI #code often includes references to non-existent dependencies. These references are commonly called “#hallucinations”. A new type of #attack has arisen that involves an attacker registering a package whose name is frequently hallucinated. When AI code containing this #hallucination is accepted, and this dependency is installed, the attacker can ship #malicious code into the project’s build, introducing a major #security vulnerability. This type of attack has become known as “#slopsquatting”.

Фантазии LLM воплощаются в реальности — фальшивые опенсорсные библиотеки

LLM придумывает названия несуществующих библиотек и предлагает разработчикам-вайбкодерам пользоваться ими. Если есть спрос — возникнет и предложение. Вскоре эти библиотеки действительно появляются в реальности , но уже с вредоносным кодом.

https://habr.com/ru/companies/globalsign/articles/946872/

#llm #галлюцинации #slopsquatting #генерация_кода #фальшивки

Фантазии LLM воплощаются в реальности — фальшивые опенсорсные библиотеки

Использование галлюцинаций LLM для распространения вредоносного кода через опенсорсные репозитории В результате галлюцинаций чатботов в интернете возникли потоки трафика к несуществующим сайтам в...

Хабр

**Check this out: techno feudalism, chatons, slopsquatting and more (9. 8. 2025)**

(Self-sustainable organic farms (and self-hosted IT stuff) are a nice idea, but they are difficult to maintain in ‘island mode’. Are community owned shared data servers a solution?)

(Examples of community data servers in France)

(If you’re masochistic enough to join FOSS development and don’t know where to start, well, you can do it here. A list of open issues that are ‘easy’ solvable.)

(If you’re using LLM for code generation and then you install a non-existing library (that is hosted by the attacker), well, it’s your own fault.)

(You want to see what are your neighbours’ devices, like garage opener, up to? )

(You never know when you need retro-style display fonts)

(Windows 10 support is running out soon. Don’t buy a new computer, shoot yourself in the foot with a Linux! You will limp, but you’ll be free from mass-scale espionage.)

(Forget AI detector tools, hoomanz are also able to detect AI slop. Actually, the signs of slop are pretty straight forward. AI sounds like you listened to a hyped ultra positive grifter salesman/politician)

https://blog.rozman.info/check-this-out-techno-feudalism-chatons-slopsquatting-and-more-9-8-2025/

#endof10 #fonts #FOSS #homeassistant #LLM #slopsquatting

The Future is NOT Self-Hosted

In a world where corporations have detached buying from owning, one man attempts to do something radical: build his own cloud.

Drew Lyton

"#Slopsquatting is a type of #cybersquatting. It is the practice of registering a non-existent software package name that a large language model (#LLM) may hallucinate in its output, whereby someone unknowingly may copy-paste and install the #software package without realizing it is #fake."

https://en.wikipedia.org/wiki/Slopsquatting

Slopsquatting - Wikipedia

Ok, ich lass mich mal zu einer #Prophezeiung hinreißen.

#Slopsquatting ist ja ein alter Hut.

Aber was haltet ihr von #Slopswatting? Also das gezielte Platzieren von Falschinfos im Internet, sodass AI-aided Policing-Systeme kunkludieren, dass eine bestimmte Person ein ganz gefährlicher Gefährder ist, den man mal hochnehmen sollte?

#LLM can't stop making up software dependencies and sabotaging everything
Hallucinated package names fuel '#slopsquatting'
As #AI #coding assistants invent nonexistent software libraries to download and use, enterprising attackers create and upload libraries with those names—laced with #malware, of course.
https://www.theregister.com/2025/04/12/ai_code_suggestions_sabotage_supply_chain/
LLMs can't stop making up software dependencies and sabotaging everything

: Hallucinated package names fuel 'slopsquatting'

The Register

📢 AI coding tools are creating silent vulnerabilities through "slopsquatting"—where attackers register package names hallucinated by AI.
This attack vector “exploits vibecoding" (using AI without review) and specifically targets less technical developers. 

#AISecurityRisks #Slopsquatting #VibeCoding #SecureCoding #CyberSecurity

https://www.lotharschulz.info/2025/05/12/the-hidden-poison-in-ai-generated-code-how-vibecoding-enables-slopsquatting-attacks/

The hidden poison in AI-generated code: How vibecoding enables slopsquatting attacks – Lothar Schulz