Five major LLMs consistently hallucinate the same 127 nonexistent Python and npm package names
According to CSO Online, researcher Aleksandr Churilov found that Claude, Codex, Gemini, and two other LLMs generate identical hallucinated library names across PyPI and npm repositories in his paper "The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort." The finding exposes enterprise developers to slopsquatting attacks, where attackers create malicious packages matching the hallucinated names and incorporate them into legitimate applications.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.