← the record
WF-HW23LM

Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

Large language models have reportedly hallucinated non-existent software package names, some of which were subsequently uploaded to public repositories and incorporated into real codebases. In one case, a package named huggingface-cli, which was purported to have been originally suggested by an AI model, was downloaded more than 15,000 times. This dynamic enables what security researchers have termed "slopsquatting," in which attackers register hallucinated package names and introduce potential malware into software supply chains.

Date it happened
2023-12-01
Organisation involved
Developers using AI-generated suggestions, Bar Lanyado
Product, system or model
Python Package Index (PyPI), npm (Node.js), LLM-powered coding assistants, LLaMA, Google Search / AI Overview, GitHub, Gemini Pro, DeepSeek Coder, Command, CodeLlama, BLOOM, GPT-4, GPT-3.5
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.