
YOUR AI
HALLUCINATED
A BACKDOOR.
// Slopsquatted packages in your manifest.
// Scan them. Roast the AI. Don't get pwned.
Roast My Code.
Paste your package.json, requirements.txt, or source code and let Spectre — our security ghost — tear into your dependencies, then tell you exactly how to fix them.
Darkly humorous. Technically accurate. Free with login.
Roast My Code
Horror Stories
The package had 50k weekly downloads and was still malicious
## The Twist This one wasn't an AI hallucination. The AI suggested `node-cache-wrapper`. It had 50,000 weekly downloads...
My therapist said to talk about it: the package that drained my Stripe keys
## The Mistake Solo founder. 1am. ChatGPT suggested `stripe-webhook-utils` to handle signature verification. It worked....
PyPI phantom package stole our AWS credentials — $34k bill overnight
## Context I was onboarding a junior dev and we were pair-programming with Claude 3. We asked for help setting up async...
A 'helpful' requirements.txt from ChatGPT installed a keylogger on every dev laptop
## Context Junior dev asked ChatGPT to scaffold a Django REST endpoint. It generated a clean requirements.txt including...
How an AI-hallucinated npm package almost took down our production API
## The Setup It was 2am on a Friday. Our startup was two weeks from launch and I was frantically asking ChatGPT how to ...
We got SOC2 certified. Then an AI suggested a package that leaked our audit logs.
## The Irony We'd just passed SOC2. Our auditor recommended centralizing compliance logs. An engineer asked an AI for a...
Got a horror story?
Share your slopsquatting encounter. Warn other devs. Earn your badge.
Threat Detection Trends
● LIVE
New slopsquatting threats and encyclopedia entries detected by DevHorrors.
Top Threats
Install once. Block slopsquatted packages from every pull request automatically.
See Plans →Drop our GitHub Actions step into any pipeline. Fail builds on critical threats.
View Docs →Know the second
your site goes dark.
Add any URL and DevHorrors watches it around the clock. The moment it goes down — or recovers — you get a branded email alert with response codes, timestamps, and a one-click link to your dashboard.
Built by devs, for devs.
No enterprise sales calls.
Snyk is great for enterprises. DevHorrors is great for developers. Scan for free, integrate in minutes, and only pay when you need automation at scale.
# Install the DevHorrors CLI
npx devhorrors scan
# Or scan a specific manifest
npx devhorrors scan package.json
# Scan a code snippet
npx devhorrors scan --snippet import("crypto-utils")Is Your Project Safe?
Paste your package.json, requirements.txt, go.mod, or Gemfile. We'll check every dependency instantly.