Hey folks! Sharing something I've been working on.
Like a lot of devs lately, I've been seeing more cases of "slopsquatting": AI coding assistants confidently suggesting package names that look real but don't exist, which then get registered by bad actors. A few have alr
Like a lot of devs lately, I've been seeing more cases of "slopsquatting": AI coding assistants confidently suggesting package names that look real but don't exist, which then get registered by bad actors. A few have already made it into production package.json/requirements.txt files.
So I built DevHorrors, a free scanner that checks your manifest (npm, PyPI, Go, RubyGems) against a curated database of known hallucinated, typosquatted, and malicious packages. It also has a "Roast Engine" that gives you a (darkly humorous) security critique of your dependencies, alongside the actual remediation steps.
What it does:
- Paste/upload a manifest or repo โ instant risk report per dependency
- Hallucination-confidence scores and the legitimate package to swap to
- A public threat feed + community "horror stories" from devs who got hit
- Free API + CLI for CI/CD
It's free to use; there's a paid tier for team monitoring, Slack/Discord alerts, and GitHub PR blocking. I'm genuinely curious how others are handling this โ is anyone here actively checking for AI-hallucinated packages in their pipelines, or relying on registries to catch it?
Site: devhorrors.com ยท would love honest feedback, especially on what's missing for your stack.
Thanks! Have a good day!
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.