https://shipreadyai.dev/incidents/slopsquatting-npm-campaign

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Slopsquatting campaign on npm

2026-02. npm.

## What happened

The sources report 126 malicious npm packages exploiting AI-hallucinated package names.
A USENIX study of 2.23 million samples found 19.7 percent referenced a package that did not exist.

## What ShipReady can say

A URL check reads a published app, not its dependency tree. Dependency scanning belongs to the platform and to the Release Gate checklist.

## Sources

- [daily.dev summary of the crackr.dev directory](https://app.daily.dev/posts/vibe-coding-failures-documented-ai-code-incidents-wjx2mwbpj)
- [CatDoes vibe coding security checklist](https://catdoes.com/blog/vibe-coding-security-checklist)
- [Arnica vibe coding security risks](https://www.arnica.io/blog/vibe-coding-security-risks)
