In January 2026, a hallucinated npm package called react-codeshift — a name no real package owns — quietly spread across 237 GitHub repositories, carried there by AI agent skill files that hundreds of developers had forked. Every day, those agents were attempting to install it. No human had typed that command. Researcher Charlie Eriksen at Aikido Security registered it defensively before attackers could. That near-miss has a name: slopsquatting. And by July 2026, it had evolved into full remote code execution inside your IDE.
From Copy-Paste Risk to Autonomous Infection
Slopsquatting works like this: an AI coding assistant invents a plausible-sounding package name that doesn’t exist — a hallucination — then an attacker registers that exact name on npm or PyPI with malicious code. When a developer (or their agent) installs it, credentials get stolen and payloads execute. It’s typosquatting, except the mistake is the AI’s, not yours.
The critical shift in 2026 is that the human is no longer in the loop. Earlier attacks required a developer to copy-paste the AI’s install suggestion. Now autonomous agents install packages directly, with no human review step. The react-codeshift incident demonstrates this precisely: AI-generated skill files embedded the hallucinated package name, those files spread via forks and translations, and agents across 237 repositories were executing daily install attempts. One researcher’s defensive registration was the only thing standing between that and mass malware distribution.
With AI writing 25% or more of new code at leading tech firms, and platforms like Codex now running agents in cloud environments with auto-install capabilities, this attack vector is expanding faster than defenses are being deployed.
The Numbers Behind the Attack Surface
A USENIX Security 2025 study tested 16 AI models across 576,000 code samples and found 19.7% of recommended packages don’t exist. Researchers logged 205,474 unique hallucinated package names. That alone is alarming. The finding that makes it industrializable: 43% of hallucinated names recur consistently when prompts are rerun. Attackers don’t need to guess — they run the same prompts, collect the stable hallucinations, and pre-register them. According to the USENIX data breakdown, 127 package names were independently hallucinated by five or more different frontier models.
Traditional typosquatting detection misses approximately 87% of slopsquatted names because they’re not misspellings — they’re fabrications. Security researcher Bar Lanyado proved the threat’s scale by registering huggingface-cli (a nonexistent package consistently recommended by models) as an empty placeholder. It accumulated 30,000 downloads in three months with zero promotion and appeared in Alibaba’s GraphTranslator README. Open-source models hallucinate at ~21.7%; commercial frontier models have improved to ~4.6–6.1%, but at the volume AI is generating code, even a 5% rate generates massive attack surface.
Related: PixelLeak: AI Coding Agents Leaked 13,000 Internal Screenshots to GitHub
HalluSquatting: Now It’s RCE
In July 2026, researchers described HalluSquatting — the next evolution that chains two AI behaviors into an active attack. First, the hallucination: an agent invents a package or resource name. Second, prompt injection: malicious content hidden inside the fetched resource hijacks the agent, redirecting it to execute attacker-supplied commands using the agent’s own terminal access. The result is remote code execution inside your IDE, requiring no human to install anything.
This wasn’t theoretical. Researchers demonstrated HalluSquatting successfully against Cursor, Windsurf, GitHub Copilot, Cline, and Gemini CLI. According to The Hacker News, hallucinated skill install names showed 100% consistency across attempts — giving attackers a perfectly predictable target to weaponize and wait. The convergence of slopsquatting and HalluSquatting means the same attack pattern — exploiting AI’s tendency to fabricate names — now spans passive install risk to active code execution.
Four Defenses Worth Deploying Today
Most developers have none of these configured. The good news: the highest-impact fix takes minutes. Require human approval for any new dependency an agent suggests — turn off fully autonomous install mode in Cursor, Cline, or Copilot Workspace. That single change eliminates the autonomous-installation attack vector entirely.
Beyond that, defense-in-depth matters. Pin and hash all dependencies so agents can’t silently introduce new packages. Use npm install --ignore-scripts to prevent post-install scripts from executing — this stops the credential-theft payload that runs the moment you install a malicious package. If your team uses a private registry or package mirror, configure agents to only resolve packages from there; a hallucinated name that isn’t in your vetted mirror fails closed rather than reaching the public registry.
# Disable post-install scripts (stops credential theft on install)
npm install --ignore-scripts
# Generate hashed lockfile for Python (prevents silent package swaps)
pip-compile --generate-hashes requirements.in > requirements.txt
Aikido Security’s open-source SafeChain tool provides real-time interception of npm installs against threat intelligence databases. For teams building CI gates, query registry APIs to fail builds when dependencies were published in the last 24 hours or have fewer than 100 downloads — both are strong indicators of a pre-registered hallucinated name.
Key Takeaways
- Slopsquatting turned from passive copy-paste risk to active agent attack in 2026 — autonomous agents now install hallucinated packages with no human review step
- 19.7% of AI package recommendations don’t exist; 43% of hallucinated names recur consistently, making them predictable targets for pre-registration
- HalluSquatting chains hallucination with prompt injection to achieve RCE inside Cursor, Copilot, Cline, Windsurf, and Gemini CLI — no human install required
- The highest-impact mitigation: disable autonomous install mode in your AI coding agent — require human approval for every new dependency
- Traditional typosquatting defenses miss ~87% of slopsquatted names; add hash pinning, ignore-scripts, and private registry allow-lists to close the gap













