Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••••
Reverse EngineeringReverse-engineered 8BitDo firmware encryption(27.09.2026 um 01:18 Uhr)
••••
Sichere ProgrammierungHow Hindsight Turned Deployment #1017 Into the Fix for #1057(29.09.2026 um 06:25 Uhr)
••••••
Reverse EngineeringReverse-engineered 8BitDo firmware encryption(27.09.2026 um 01:18 Uhr)
••••
Sichere ProgrammierungHow Hindsight Turned Deployment #1017 Into the Fix for #1057(29.09.2026 um 06:25 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

🎭 Slopsquatting: The Supply Chain Attack Hiding in Plain Sight

Your AI coding assistant just suggested a package that doesn't exist. An attacker is about to register it with malware. Researchers analyzed 576,000 AI-generated code samples and found something terrifying: → 205,474 unique "phantom p…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Your AI coding assistant just suggested a package that doesn't exist. An attacker is about to register it with malware.

Researchers analyzed 576,000 AI-generated code samples and found something terrifying:

→ 205,474 unique "phantom packages" that don't exist in PyPI/npm

→ 43% repeat PERFECTLY across identical prompts

→ Commercial AI (GPT-4, Claude, Copilot): 5.2% hallucination rate

→ Open-source LLMs: 21.7% hallucination rate



This isn't typosquatting. It's slopsquatting - exploiting systematic AI behavior.



The attack is trivial:

Query AI assistant with common prompts

Collect hallucinated package names

Register them on PyPI/npm with malicious code

Wait for developers to pip install your malware



Here's what makes this surreal:

Despite 6 months of security research, 205K identified targets, and trivial exploitation... zero confirmed attacks exist in the wild.

The window for defense is open. But it's closing fast.

I wrote a deep-dive on:

✓ Why AI reliably hallucinates the same phantom packages

✓ Which security tools detect this (spoiler: almost none)

✓ A 15-minute scanner you can deploy today

✓ Why zero attacks won't last much longer



https://lnkd.in/dw6R2qSN



If you're using AI coding assistants (and you probably are), this affects you.



Read it before the first confirmed attack makes headlines.



Disclaimer: Personal analysis based on my cybersecurity background. Not legal advice. Views are my own.



hashtag#CyberSecurity hashtag#AppSec hashtag#AI hashtag#DevSecOps hashtag#SupplyChainSecurity hashtag#SoftwareDevelopment hashtag#InfoSec hashtag#DevOps

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 🎭 Slopsquatting: The Supply Chain Attack Hiding in Plain Sight

Thematisch verwandte Begriffe: Slopsquatting, Supply, Chain, Attack · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102367 | mall4j through 4.0 contains an insufficient session expiration vulnerab…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag