Author here. While building automated security remediation, we discovered AI models hallucinating package names at a 19.6% rate (USENIX 2025). Attackers are already exploiting this - "huggingface-cli" got 30,000 downloads despite being fake.
The security industry focuses on detection, but with AI generating code 10x faster, we need automated fixes that match that speed. Otherwise we're just letting all those issues rot in the backlog.
Happy to answer questions about slopsquatting, our technical approach, or the state of AI code security.
Arubis•4h ago
The security industry focuses on detection, but with AI generating code 10x faster, we need automated fixes that match that speed. Otherwise we're just letting all those issues rot in the backlog.
Happy to answer questions about slopsquatting, our technical approach, or the state of AI code security.
More details on building this in the open: https://www.indiehackers.com/post/built-the-wrong-thing-at-t...