Discussion about this post

User's avatar
Mitchell Kosowski's avatar

The slopsquatting angle is what really got me.

We've spent years worrying about compromised maintainers, but the idea that attackers can just register the fake package names that AI models consistently hallucinate and then sit back while AI-driven workflows deliver 30k downloads feels like a fundamentally new class of threat.

It's not exploiting trust in the supply chain, it's exploiting trust in the AI's suggestions.

Joe's avatar

As a recommendation, I ran this article through Claude Code and had it update my Claude.md to have specific settings to check packages before installing and user gates for myself

5 more comments...

No posts

Ready for more?