AI incident ·
Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers
In brief
An AI system built by Openai, Meta and 4 others and deployed by Developers Using Ai Generated Suggestions and Bar Lanyado allegedly harmed Users Downstream Of Software Contaminated By Hallucinated Packages, Trust In Open Source Repositories And Ai Assisted Coding Tools and 4 others.
- Risk domain
- Misinformation
- Occurred
- Coverage
- 4 reports
What happened
Large language models have reportedly hallucinated non-existent software package names, some of which were subsequently uploaded to public repositories and incorporated into real codebases. In one case, a package named huggingface-cli, which was purported to have been originally suggested by an AI model, was downloaded more than 15,000 times. This dynamic enables what security researchers have termed "slopsquatting," in which attackers register hallucinated package names and introduce potential
Laws that address this harm
Policy angle: Classified under Misinformation (False or misleading information) in the MIT AI Risk Repository taxonomy; 5 recorded instruments address this use case.
- India DPDP Act
- Law on Artificial Intelligence (2025)
- Law No. 132/2025 on artificial intelligence
- EU AI Act
- Texas Responsible AI Governance Act (TRAIGA)
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (4)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Developers Using Ai Generated Suggestions, Bar Lanyado
- Alleged developer
- Openai, Meta, Google, Deepseek Ai, Cohere, Bigscience
- Alleged harmed party
- Users Downstream Of Software Contaminated By Hallucinated Packages, Trust In Open Source Repositories And Ai Assisted Coding Tools, Software Ecosystems, Organizations That Incorporated Fake Dependencies, Developers And Businesses Incorporating Ai Suggested Packages, Alibaba
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- Misinformation
- Risk subdomain
- 3.1 False or misleading information
- Causal entity
- AI
- Intent
- Unintentional
- Timing
- Post-deployment
- Harm level
- —
- Sectors
- —
- Countries
- —
Risk entries describing this failure mode
Entries from the MIT AI Risk Repository coded to subdomain 3.1.
- Pursuing Consistent Context
"LLMs have been demonstrated to pursue consistent context [129]–[132], which may lead to erroneous generation when the prefixes contain false information. Typical examples include sycophancy [129], [130], false demonstra...
- Defective Decoding Process
In general, LLMs employ the Transformer architecture [32] and generate content in an autoregressive manner, where the prediction of the next token is conditioned on the previously generated token sequence. Such a scheme...
- Noisy Training Data
"Another important source of hallucinations is the noise in training data, which introduces errors in the knowledge stored in model parameters [111]–[113]. Generally, the training data inherently harbors misinformation....
- Hallucinations
"LLMs generate nonsensical, untruthful, and factual incorrect content"
- Faithfulness Errors
"The LLM-generated content could contain inaccurate information" which is is not true to the source material or input used
- Factuality Errors
"The LLM-generated content could contain inaccurate information" which is factually incorrect
- Untruthful Content
"The LLM-generated content could contain inaccurate information"
- Knowledge Gaps
"Since the training corpora of LLMs can not contain all possible world knowledge [114]–[119], and it is challenging for LLMs to grasp the long-tail knowledge within their training data [120], [121], LLMs inherently posse...
Incidents in the same risk subdomain
- Nonfiction Book 'The Future of Truth' Reportedly Included AI-Generated and Misattributed Quotations
- Claude Console Reportedly Generated Phantom Legal Quotations in Trump Layoffs Court Filing
- Purportedly AI-Enhanced Images of Iranian Women Protesters Were Reportedly Spread With Unverified Execution Claims
- South Africa Draft National AI Policy Reportedly Included Fictitious References Believed to Be AI Hallucinations
- Purportedly AI-Generated Image Reportedly Misled Daejeon Authorities Searching for Escaped Wolf Neukgu
- Gemini and Grok Reportedly Misidentified Authentic Minab School-Strike Graveyard Photo as Unrelated Disaster Imagery
Source record: incident #731 on the AI Incident Database · all 4 reports