AI coding assistants are accelerating development, but they are also introducing unvetted or hallucinated dependencies that can lead to slopsquatting and supply-chain compromise. The article argues that enterprises must govern package selection before code reaches the build stage, with ActiveState positioning its curated catalog as a way to block risky dependencies at intake. #ActiveState #PyPI #npm #react-codeshift
Keypoints
- AI-generated dependency suggestions can create supply-chain risk before code is even built.
- Slopsquatting happens when attackers register hallucinated package names on PyPI or npm.
- Researchers observed the npm package react-codeshift spreading through AI-generated agent skills and repositories.
- Open source maintainers face more pressure as AI-assisted pull requests increase review burden and defects.
- Enterprises need ingestion controls, curated catalogs, and pre-vetted packages to secure the pipeline.