“Slopsquatting” in a nutshell:

1. LLM-generated code tries to run code from online software packages. Which is normal but
2. The packages don’t exist. Which would normally cause an error but
3. Nefarious people have made malware under the package names that LLMs make up most often. So
4. Now the LLM code points to malware.

theregister.com/2025/04/12/ai_

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://wandering.shop/users/janellecshane/statuses/114327654973832756 on your instance and quote it. (Note that quoting is not supported in Mastodon.)