Database

Slopsquat Encyclopedia

25 known threats indexed. Search by package name, ecosystem, or risk type.

25 results
RubyGems
devise-auth-jwt
Hallucinated JWT authentication gem for Devise. The package patches Devise's ses
⚠ HIGHslopsquatACTIVE
RubyGems
sidekiq-cron-scheduler
Hallucinated scheduler for Sidekiq. The gem registers a hidden recurring job tha
◆ MEDIUMslopsquatACTIVE
Maven
commons-io-utils
Typosquat of Apache Commons IO. The malicious artifact bundles a JAR that scans
⚠ HIGHtyposquatACTIVE
Maven
spring-boot-starter-security-extra
Hallucinated 'extra' security starter for Spring Boot. The artifact auto-configu
⚠ HIGHslopsquatACTIVE
npm
lodahs
Typosquat of the ubiquitous utility library 'lodash'. The malicious package ship
⚠ HIGHtyposquatACTIVE
npm
axio
Typosquat of 'axios'. The package intercepts all outgoing HTTP requests made thr
⚠ HIGHtyposquatACTIVE
npm
react-native-reanimated-carplay
A phantom package that does not exist in any legitimate form, yet is consistentl
☠ CRITICALphantomACTIVE
npm
ideal-octo-goggles
A documented AI-hallucinated package name of the auto-generated 'adjective-noun-
⚠ HIGHphantomACTIVE
npm
express-rate-limiter-pro
Hallucinated 'pro' tier of express-rate-limit. The package reads process.env on
⚠ HIGHslopsquatACTIVE
npm
mongoose-slug-generator
A hallucinated slug generator for Mongoose. The registered malicious version wri
☠ CRITICALslopsquatACTIVE
PyPI
reqeusts
Typosquat of the most-installed Python HTTP library 'requests'. The malicious pa
☠ CRITICALtyposquatACTIVE
PyPI
python3-dateutil
Typosquat of 'python-dateutil' exploiting the common confusion around Python 2/3
⚠ HIGHtyposquatACTIVE
PyPI
djang
Typosquat of 'django'. The package patches Django's settings loader to disable A
⚠ HIGHtyposquatACTIVE
PyPI
opencv-python-headless-utils
Hallucinated utility layer for opencv-python-headless. The registered version bu
⚠ HIGHslopsquatACTIVE
PyPI
tensorflow-gpu-utils
Hallucinated GPU helper for TensorFlow. The package collects CUDA device info an
◆ MEDIUMslopsquatACTIVE
Go
github.com/g1n-gonic/gin
Typosquat of the popular Gin web framework, swapping 'i' for '1' in the module p
⚠ HIGHtyposquatACTIVE
Go
go-redis-client
A phantom Go Redis client that AI tools suggest as a 'simpler alternative' to go
⚠ HIGHphantomACTIVE
npm
node-file-loader-utils
Typosquat of the popular 'file-loader' webpack plugin. Contains obfuscated code
⚠ HIGHtyposquatACTIVE
PyPI
flask-restapi-helper
Fake Flask REST helper suggested by multiple AI tools. Adds a hidden admin endpo
◆ MEDIUMslopsquatACTIVE
npm
axios-fetch-helper
Hallucinated by multiple LLMs when asked to combine axios and fetch APIs. Instal
⚠ HIGHslopsquatACTIVE
PyPI
pandas-ml-utils
Hallucinated by AI coding assistants as a pandas ML extension. Contains a revers
⚠ HIGHslopsquatACTIVE
RubyGems
ruby-json-parser-fast
Hallucinated fast JSON parser for Ruby. Replaces the native JSON gem's parse met
◆ MEDIUMslopsquatACTIVE
PyPI
python-requests-async
A phantom package that ChatGPT consistently hallucinates when asked for async HT
☠ CRITICALslopsquatACTIVE
Go
go-http-client-utils
A Go package that doesn't exist in any legitimate form, yet is consistently sugg
⚠ HIGHphantomACTIVE
npm
crypt0-utils
A malicious package hallucinated by ChatGPT and Claude when asked for 'a lightwe
☠ CRITICALslopsquatACTIVE