·The mirago team
What Is Slopsquatting? The AI Supply-Chain Attack, Explained
Slopsquatting is a new supply-chain attack that weaponises the package names AI coding tools hallucinate. Here's how it works and how to defend against it.
Read →Topic
Software supply-chain security for Python.
Slopsquatting is a new supply-chain attack that weaponises the package names AI coding tools hallucinate. Here's how it works and how to defend against it.
Read →AI assistants are now a major source of new dependencies. Here's how to harden your Python supply chain against the risks they introduce.
Read →Make import-checking automatic. Here's how to run mirago in GitHub Actions so an AI-invented package fails the build before it merges.
Read →Typosquatting bets on your typos; slopsquatting bets on AI's hallucinations. Here's how the two supply-chain attacks differ — and overlap.
Read →Not every real package is a safe one. Five red flags that an AI-suggested PyPI package could be a slopsquat — and how mirago spots them.
Read →