Summary
Slopsquatting is an emerging cybersecurity threat in the software supply chain, where AI coding tools' hallucinations generate fictitious package names that attackers register with malicious code. This new attack vector exploits LLMs' tendency to create plausible but non-existent software packages, allowing malware to be injected directly into developers' codebases.