Bottom line: Five leading LLMs consistently hallucinate the same 127 package names, of which 53 remain available for registration and pose a slopsquatting risk.
Researcher Aleksandr Churilov has demonstrated that five leading Large Language Models (Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2) invent identical fictitious package names. This consistency creates elevated security risk through so-called slopsquatting, in which attackers distribute malware under these hallucinated names.
In his not yet peer-reviewed study “The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort,” Churilov documents the discovery of 127 package names that are consistently hallucinated by all five models examined. This convergence is unusual, given that these are independent Large Language Models.
Of these 127 names, 53 packages remained available for registration in April 2026: 41 on PyPI and 12 on npm. These packages could be registered by attackers and weaponized with malware to inject them into legitimate applications—the classic slopsquatting attack.
Churilov identifies two mechanisms behind this convergence: First, the models may have learned the same false package references from shared training data, such as public tutorials and documentation. Second, they may independently extrapolate plausible names based on ecosystem conventions and thus generate names that appear correct without actually existing.
To date, research has found no evidence that attackers have already maliciously registered these 53 remaining package names or deployed them in attacks. Nevertheless, the findings reveal a structural risk: if multiple AI coding tools recommend identical fictitious dependencies, the attack window for threat actors expands considerably, and the likelihood of successful exploitation increases.
Source: www.csoonline.com · Published 24 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.