Large language models sometimes recommend libraries that do not exist. Because the same fake names recur, attackers can predict and register them on public registries, waiting for AI-assisted developers to install them.
How slopsquatting works:
Coding agents raise the risk because they can install dependencies autonomously, without a developer reviewing each package name. One hallucinated import can compromise a build pipeline.
Defenses include allowlisting registries and packages, verifying package age and reputation, blocking installs of unknown packages by agents, and scanning dependencies before use.
How PointGuard AI Helps
PointGuard AI Agentic Endpoint Security governs what coding agents can install and execute on developer machines, and AI Security Posture Management supports supply chain visibility across AI components. Policy can block agents from installing unvetted packages.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.