Close Menu
Breaking News in Technology & Business – Tech Geekwire

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    No title available in the original content

    July 3, 2025

    Amazon CEO Warns of Workforce Reduction Due to Generative AI Rollout

    July 3, 2025

    Tech in Asia Organization Profile

    July 3, 2025
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech GeekwireBreaking News in Technology & Business – Tech Geekwire
    • New
      • Amazon
      • Digital Health Technology
      • Microsoft
      • Startup
    • AI
    • Corporation
    • Crypto
    • Event
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech Geekwire
    Home ยป New Supply Chain Attack ‘Slopsquatting’ Exploits AI-Generated Code
    AI

    New Supply Chain Attack ‘Slopsquatting’ Exploits AI-Generated Code

    techgeekwireBy techgeekwireApril 21, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    Cybersecurity researchers have identified a new type of supply chain attack called ‘Slopsquatting,’ which exploits hallucinations in generative AI models used for code generation. A research team from the University of Texas at San Antonio, Virginia Tech, and the University of Oklahoma analyzed 16 code-generation models, including GPT-4, GPT-3.5, CodeLlama, DeepSeek, and Mistral, and found that approximately 20% of the recommended packages were non-existent.

    The Slopsquatting Threat

    The researchers noted that the reliance on centralized package repositories and open-source software in programming languages like Python and JavaScript, combined with AI-generated code, creates a new threat vector. Threat actors can register hallucinated package names and distribute malicious code, potentially leading to widespread compromise if a single widely-recommended hallucinated package is registered by an attacker.

    Key Findings

    • 19.7% (205,000) of recommended packages in test samples were found to be non-existent
    • Open-source models like DeepSeek and WizardCoder hallucinated more frequently (21.7% on average) compared to commercial models (5.2%) like GPT-4
    • CodeLlama was the worst offender, hallucinating over a third of its outputs
    • GPT-4 Turbo was the best performer with only 3.59% hallucinations

    Characteristics of Hallucinations

    The study found that these hallucinations were persistent, repetitive, and semantically convincing. When researchers reran 500 prompts that had previously produced hallucinated packages, 43% of hallucinations reappeared consistently across 10 successive runs. The hallucinated package names showed moderate string similarity to real packages, making them more believable.

    Protective Measures

    To mitigate this threat, security experts recommend that developers implement dependency scanners before production and runtime to detect malicious packages. The study emphasizes that rushing through security testing increases the risk of AI model hallucinations, highlighting the need for rigorous validation of AI-generated code recommendations.

    AI cybersecurity Slopsquatting software development Supply Chain Attack
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techgeekwire
    • Website

    Related Posts

    No title available in the original content

    July 3, 2025

    Amazon CEO Warns of Workforce Reduction Due to Generative AI Rollout

    July 3, 2025

    Tech in Asia Organization Profile

    July 3, 2025

    Healthline Media LLC to Pay $1.55 Million for Protecting User Health Information

    July 3, 2025

    Beijing Fourth Paradigm Technology Co. Ltd. Class H Holds Successful Annual General Meeting

    July 3, 2025

    Amazon CEO Warns Employees of Job Cuts as Company Focuses on AI Advancements

    July 3, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    No title available in the original content

    July 3, 2025

    Amazon CEO Warns of Workforce Reduction Due to Generative AI Rollout

    July 3, 2025

    Tech in Asia Organization Profile

    July 3, 2025

    Healthline Media LLC to Pay $1.55 Million for Protecting User Health Information

    July 3, 2025
    Advertisement
    Demo
    About Us
    About Us

    A rich source of news about the latest technologies in the world. Compiled in the most detailed and accurate manner in the fastest way globally. Please follow us to receive the earliest notification

    We're accepting new partnerships right now.

    Email Us: info@example.com
    Contact: +1-320-0123-451

    Our Picks

    No title available in the original content

    July 3, 2025

    Amazon CEO Warns of Workforce Reduction Due to Generative AI Rollout

    July 3, 2025

    Tech in Asia Organization Profile

    July 3, 2025
    Categories
    • AI (2,692)
    • Amazon (1,055)
    • Corporation (990)
    • Crypto (1,128)
    • Digital Health Technology (1,077)
    • Event (523)
    • Microsoft (1,224)
    • New (9,549)
    • Startup (1,160)
    © 2025 TechGeekWire. Designed by TechGeekWire.
    • Home

    Type above and press Enter to search. Press Esc to cancel.