ixsoftum
AI-assisted development

An AI coding agent suggested a malware package. A GitHub check caught it

Published 20 Aug 2026, 16:02 UTC
Ava Harlan
Ava HarlanStaff writer
Share
An AI coding agent suggested a malware package. A GitHub check caught it

A developer at Softjourn, a software consulting firm, asked an AI coding agent to recommend a package for a routine task. The agent returned a name that looked like any other library. The developer almost installed it.

Sergiy Fitsak, Softjourn's managing director, said the package had barely any downloads and had been published only days earlier. The team caught it because company policy requires checking a recommended package's source on GitHub before installing, and that check is what stopped the install.

Fitsak calls the underlying pattern "slopsquatting": AI models sometimes hallucinate package names that sound plausible but don't actually exist, and attackers register those exact names on public registries, betting a coding agent will suggest the same name to some other developer later. Once a hallucinated name shows up often enough across a model's outputs, it becomes a predictable target to squat on.

The fix costs almost nothing. Before installing anything a coding agent recommends, check the package's download count and read its source on GitHub, especially for a name that isn't already familiar. Fitsak's framing: "It takes a few extra minutes. Skipping that step once is how a team ends up explaining a supply chain compromise instead of shipping a feature on time."

Slopsquatting doesn't require a model bug a vendor can patch. It exploits how these agents generate plausible-sounding output by design, package names included. Any team running an AI coding agent against a real dependency install is exposed to the same pattern until source verification becomes a standing step in the workflow, not an optional one.