Skip to content

npm · 2026-02

Slopsquatting campaign on npm

126 malicious npm packages exploited AI-hallucinated package names.

Last updated 2026-02
Could not check

What the sources report

The sources report 126 malicious npm packages exploiting AI-hallucinated package names.

A USENIX study of 2.23 million samples found 19.7 percent referenced a package that did not exist.

Root cause class

Supply chain

Covered by

What ShipReady can say

A URL check reads a published app, not its dependency tree. Dependency scanning belongs to the platform and to the Release Gate checklist.

Sources

Related incidents

  • Could not check

    Mercor supply-chain breach

    A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026