Article
AI-Induced Supply-Chain Compromise: A Systematic Review of Package Hallucinations and Slopsquatting Attacks
2025-11-10
Abstract excerpt
<title>Abstract</title> <p>The adoption of large language models (LLMs) and AI‑assisted programming has accelerated software production, but it has also created a novel supply‑chain vulnerability: package hallucination. When an LLM generates code, it may recommend nonexistent third‑party packages that “sound” plausible. Adversaries can register these phantom names in public registries, thereby poisoning the open‑...
Topics
Open a Topic to create a Post that cites this publication.
Identifiers and source
- Literature Corpus work
- f01d3ace-6a62-59ea-a1d8-7eaf203806e0
- DOI
- 10.21203/rs.3.rs-8007192/v1
