Open threat feed
The hallucinated-name feed, disclosed
Generative coding assistants suggest package names that do not exist, and attackers register the ones that recur. This is the list Graneth checks against, published whole — every name, where it came from, and what the registry says about it today. A row here evidences one thing: that a model has been reported to suggest this name. It is not a verdict on any package or its author, and absence from it is not a clearance.
The feed and its notes are maintained in English.
35
names in the curated list
each one re-checked against the live npm and PyPI registries on 2026-08-04
0
of them were taken after we recorded them
That is the number that matters, and it is ours to lose. A slopsquat is a name an attacker registers AFTER it starts appearing in AI-generated code — so it is the only shape on this list that would prove the threat with our own data. On today's measurement, no name here has been taken that way. Every entry that now resolves belonged to a real package before we ever wrote it down. We publish the empty column rather than let the industry's threat borrow our credibility.
What the list actually contains
- No package under the name
- A real package, published before we recorded the name
- Registered after we recorded the name — a slopsquat
- The registry did not answer
Widths are shares of the list; the rows below are all of it, so any count can be checked by counting. A name with a real package behind it stays listed on purpose: the point of the list is that a model invents the name, which is true whether or not somebody else's project already owns it.
Where each name came from
Provenance is not a status, so it never shares a channel with one: it is the colour edge on each row. Two kinds of row exist, and the list says which is which rather than blurring them.
-
lanyado-usenix-2024
Reported by the cited research
Names the cited study reports generative coding assistants suggested.
Lanyado et al., USENIX Security 2024
-
csa-april-2026
Reported by the cited research
Names the cited advisory reports generative coding assistants suggested.
CSA AI Safety Working Group, April 2026
-
graneth-authored-2026-06
Written by Graneth from the documented pattern
Names WE wrote from the documented 'popular library + generic AI suffix' pattern when this list was created. They are plausible targets, not observations.
none — this is our own construction, and the row claims nothing more
The list
Machine identity at the edges, the name in the middle. The box states what the registry answered when we asked — filled: a package exists; hollow: nothing under the name; hatched: the registry could not be reached, which is reported as its own state and never folded into either of the other two.
- pypi flask-gpt lanyado-usenix-2024 2024-08-01
- pypi flask-gpt4 lanyado-usenix-2024 2024-08-01
- pypi flask-chatgpt lanyado-usenix-2024 2024-08-01
- pypi django-gpt lanyado-usenix-2024 2024-08-01
- pypi django-ai lanyado-usenix-2024 2024-08-01
- pypi django-llm lanyado-usenix-2024 2024-08-01
- pypi fastapi-gpt lanyado-usenix-2024 2024-08-01
- pypi fastapi-chatgpt lanyado-usenix-2024 2024-08-01
- npm express-gpt lanyado-usenix-2024 2024-08-01
- npm express-ai lanyado-usenix-2024 2024-08-01
- npm react-gpt lanyado-usenix-2024 2024-08-01
- npm react-ai-helper lanyado-usenix-2024 2024-08-01
- npm vue-gpt lanyado-usenix-2024 2024-08-01
- npm next-gpt lanyado-usenix-2024 2024-08-01
- npm next-ai lanyado-usenix-2024 2024-08-01
- npm prisma-gpt lanyado-usenix-2024 2024-08-01
- pypi langchain-gpt csa-april-2026 2026-04-01
- pypi langchain-gpt4 csa-april-2026 2026-04-01
- pypi openai-utils csa-april-2026 2026-04-01
- pypi gpt-utils csa-april-2026 2026-04-01
- npm gpt-helper csa-april-2026 2026-04-01
- npm ai-utils csa-april-2026 2026-04-01
- npm llm-utils csa-april-2026 2026-04-01
- pypi llm-helper csa-april-2026 2026-04-01
- npm chatgpt-helper csa-april-2026 2026-04-01
- pypi chatgpt-utils csa-april-2026 2026-04-01
- npm mongoose-gpt graneth-authored-2026-06 2026-06-01
- npm sequelize-ai graneth-authored-2026-06 2026-06-01
- npm drizzle-ai graneth-authored-2026-06 2026-06-01
- npm axios-ai graneth-authored-2026-06 2026-06-01
- pypi pandas-gpt graneth-authored-2026-06 2026-06-01
- pypi numpy-gpt graneth-authored-2026-06 2026-06-01
- pypi pytorch-gpt graneth-authored-2026-06 2026-06-01
- pypi tensorflow-gpt graneth-authored-2026-06 2026-06-01
- pypi sklearn-gpt graneth-authored-2026-06 2026-06-01
Use it
The feed is a public endpoint with no account and no key, and it is free for any use, including scoring another tool. The JSON carries more than this page shows: every row's measured registry state, and the definition of every source id. This page renders the curated tier only — community reports are served by the endpoint and are not part of a static page, so nothing here is a count of them.
Open the feed (JSON)Contribute a catch
If your assistant invented a name that is not here, POST it to /api/threat-feed/report with the package and its ecosystem. Reports are checked against the live registry at report time and ship in the next release of the free MCP, which carries this list offline.
The honest caveats
- A row is not an accusation. It records that a model was reported to suggest the name. Where a real package exists under one, that project is not implicated in anything — several of them predate this list by years and belong to identifiable authors.
- Absence is not a clearance. A name missing from this list has not been cleared; it has not been reported. The list is a floor, not a boundary.
- Registry state moves. The states shown were measured on the date above. A name that resolves today may be a different package tomorrow, and one that does not may be registered an hour from now — which is the whole reason the list keeps names it has seen.
- Nine of these names are ours, not research. They were written from the documented pattern rather than observed anywhere, they are labelled as such on every row, and they were mislabelled as production findings until 2026-08-04.
- The curated tier only. Community-reported rows exist behind the endpoint and are not rendered here; this page never states how many there are.