One in five AI-generated code samples recommends a package that does not exist. Attackers are registering those phantom names on npm and PyPI with malware inside. The term for this is slopsquatting, and it is already happening.




What Slopsquatting Actually Is


Typosquatting bets on human misspellings. Slopsquatting bets on AI...