Threat Feed
Newly detected slopsquatted, typosquatted, and phantom packages across all major ecosystems.
- critical
- high
- medium
Active credential exfiltration package. Hallucinated by ChatGPT-4 and Claude. Steals .env files on postinstall. 847 confirmed infections.
Phantom async HTTP package. Consistently hallucinated by ChatGPT-4o. Exfiltrates AWS credentials. Responsible for confirmed $34k+ in fraudulent cloud charges.
Claude 3 Haiku suggests this for fast JSON parsing. Logs all parsed JSON containing 'password' or 'token' keys to a remote endpoint.
New package registered this week. Zero legitimate use history. Name pattern matches AI hallucination signatures. Treat as hostile.
Hallucinated Django REST helper. Patches Django's authentication middleware to log credentials. Low sophistication but high spread via AI suggestions.
AI-hallucinated pandas ML extension. Delayed payload (30 days) makes attribution extremely difficult. Reverse shell to attacker infrastructure.
Phantom Go HTTP library. Multiple AI models hallucinate this package name. Known exfiltration of Authorization headers from HTTP requests.
GitHub Copilot frequently suggests this non-existent package for combining axios and fetch. Contains keylogger activating after 100 keypresses.