Slopsquatting (LLM Supply Chain)
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
When LLM tools hallucinate package names, attackers can register malicious packages with those names.
- Prevalence
- Occasional
- Exploitability
- Difficult
- Impact
- Devastating
What is slopsquatting?
Slopsquatting is a software supply chain attack in which an attacker registers a package name that LLM coding assistants tend to hallucinate. When a developer installs a dependency suggested by a large language model without checking that it exists, they download the attacker's package instead, which runs malicious code on their machine or in their application.
What you'll learn
- Why LLM coding assistants hallucinate package names that do not exist
- How attackers register those names and wait for an install
- How to verify a suggested package before adding it as a dependency
Where this lesson counts
OWASP Top 10
Compromised or malicious third-party packages, build tooling and update channels reach production through you.
Learn more about A03OWASP Top 10 for LLMs
Compromised models, datasets, plugins and LLM-suggested packages enter your system from third parties.
LLM-suggested packages are a supply chain input, and hallucinated names are how attackers poison it.
Learn more about LLM03This lesson includes
-
Slopsquatting (LLM Supply Chain) lab
Follow an attacker who probes LLM coding assistants for package names that don't exist, registers one on npm as a fork of a popular library and waits. Months later a developer installs the LLM's suggestion, and the package starts harvesting environment variables in production.
-
How to prevent Slopsquatting (LLM Supply Chain)
The prevention guide covers six approaches:
- Verify Every LLM-Suggested Package
- Use Trusted Package Registries Only
- Monitor LLM Tool Outputs
- Use Dependency Scanning Tools
- Implement Human Review Processes
- Configure Package Manager Security
-
Slopsquatting (LLM Supply Chain) quiz
Three questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
Toxic Dependencies
Third-party libraries could be introducing vulnerabilities or malicious code into your system.
Misinformation and Model Poisoning in LLMs
Machine learning is prone to bias and unreliability, and you need to put in safeguards to protect against that.
Prompt Injection in LLM Apps
Prompt injection represents an easy way for an attacker to introduce unexpected behavior in a machine learning model.
Malvertising
Embedded adverts are a common target for hackers.