About DevHorrors โ€” AI Package Hallucination Detection & Slopsquat Encyclopedia
About DevHorrors

We Track What
AI Gets Wrong.

// DevHorrors is the definitive community encyclopedia
// for AI-hallucinated, slopsquatted, and typosquatted packages.
// Built by devs. For devs. Against the machines.

Our Mission

Defend every npm install from AI slop.

LLMs like ChatGPT, Claude, and GitHub Copilot hallucinate package names every day. When developers blindly install those suggestions, real malware gets executed โ€” credentials stolen, pipelines hijacked, companies breached.

DevHorrors exists to close that gap. We maintain a continuously updated encyclopedia of hallucinated packages, run community-sourced horror stories as threat intelligence, and provide developer tooling to catch these threats before they ship.

We believe in open knowledge: the encyclopedia is free. The scanner is free. The community is free. Advanced CI/CD protection and enterprise features fund the mission.

Slopsquat Detection

The first public database of AI-hallucinated package names, continuously maintained by security researchers and developers worldwide.

Real-Time Threat Intelligence

Our threat feed aggregates community reports, automated scanning, and researcher submissions into a single live feed.

Open Developer Tooling

Free scanner, GitHub Actions integration, and CI/CD scripts. Enterprise features fund free tiers for individual developers.

Spectre
Meet the Mascot

Spectre ๐Ÿ‘ป

Spectre wasn't always a ghost. Once, Spectre was a perfectly ordinary npm package โ€” react-fast-render โ€” dreamed up by a large language model late one Tuesday night. The model had never seen the package, couldn't cite a repository, and didn't know it didn't exist. It just sounded right.

A tired developer, three coffees deep, ran npm install. The package wasn't on the registry โ€” but someone had registered it the week before, knowing an AI would eventually recommend it. The install script ran silently. Credentials leaked. Pipelines broke. Spectre was born in the blast.

Now Spectre haunts the DevHorrors encyclopedia, drifting through node_modules and site-packages everywhere, leaving behind a cold trail of warnings. The mascot is a reminder: the most dangerous threats are the ones you can't see โ€” the packages that sound real, look real, even work real, but were never there at all.

"I am the ghost of every package that never existed. Boo." โ€” Spectre

Haunts
npm ยท PyPI ยท Go ยท Gems
Origin
An LLM hallucination
Mission
Warn before you install
Work With Us

Partnerships & Sponsorships

DevHorrors reaches security-conscious developers, DevSecOps engineers, and engineering leaders at every level โ€” from solo devs to Fortune 500 teams. If your product belongs in front of that audience, let's talk.

Content Sponsorship

Feature your security tool, developer platform, or service in our weekly threat digest and email newsletter. Reach 10,000+ security-aware developers who actively monitor threats.

Sponsor a Newsletter

Technology Partnership

Integrate DevHorrors threat data into your SIEM, DAST, or developer security platform. We offer a partner API tier with full encyclopedia access, webhook events, and co-marketing.

Become a Partner

Research Collaboration

Academic institutions, security labs, and threat intelligence firms: collaborate on our dataset. Joint publications, shared research credits, and access to our anonymised scan telemetry.

Research Inquiry
Get in Touch

Contact Us

Whether you're interested in enterprise security, a partnership, sponsoring our newsletter, or just want to say hello โ€” we read every message.

General Question
Partnership
Sponsorship / Advertising
Enterprise Sales
Press / Media
Response Time

Enterprise & partnership inquiries: 24h
General & press: 48โ€“72h

No spam. We use your data only to respond to your inquiry.