Security Audit Reveals AI Coding Agents Installed Unowned Code in Corporate Networks
A security audit has identified a critical supply-chain risk where autonomous coding assistants generate install commands for unregistered package names, opening doors for typosquatting attacks.
Security researchers analyzing corporate software repositories found over 200 instances where AI coding agents like Claude Code, OpenAI Codex, and Hermes suggested dependencies that did not exist in official registries at the time of code generation.
Subscribe to Tech Bytes Briefing
Get hand-curated technology analysis, major breakings, and executive summaries delivered straight to your inbox daily.
This 'slopsquatting' phenomenon allows malicious actors to register predicted package names, tricking automated deployment pipelines into downloading untrusted code into production networks.