20–30 min Updated

Slopsquatting (LLM Supply Chain)

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

When LLM tools hallucinate package names, attackers can register malicious packages with those names.

Prevalence
Occasional
Exploitability
Difficult
Impact
Devastating

What is slopsquatting?

Slopsquatting is a software supply chain attack in which an attacker registers a package name that LLM coding assistants tend to hallucinate. When a developer installs a dependency suggested by a large language model without checking that it exists, they download the attacker's package instead, which runs malicious code on their machine or in their application.

What you'll learn

  • Why LLM coding assistants hallucinate package names that do not exist
  • How attackers register those names and wait for an install
  • How to verify a suggested package before adding it as a dependency

Where this lesson counts

OWASP Top 10

OWASP Top 10 for LLMs

  • Slopsquatting (LLM Supply Chain) lab

    Follow an attacker who probes LLM coding assistants for package names that don't exist, registers one on npm as a fork of a popular library and waits. Months later a developer installs the LLM's suggestion, and the package starts harvesting environment variables in production.

  • How to prevent Slopsquatting (LLM Supply Chain)

    The prevention guide covers six approaches:

    • Verify Every LLM-Suggested Package
    • Use Trusted Package Registries Only
    • Monitor LLM Tool Outputs
    • Use Dependency Scanning Tools
    • Implement Human Review Processes
    • Configure Package Manager Security
  • Slopsquatting (LLM Supply Chain) quiz

    Three questions. Passing marks the lesson complete.

Sources