Slopsquatting: the AI supply chain attack you haven't patched
Eighty percent of new developers on GitHub start using Copilot within their first week. How many really know what it's pulling in?
AI coding assistants generate code faster than teams can review it. That gap – between the rate agents produce code and the rate that code gets properly checked – is exactly what attackers are targeting. James Matchett (Head of Security), Ralph McTeggart (Principal Engineer), and Nigel Douglas (Head of Developer Relations) at Cloudsmith explain three escalating risks: how AI expands the attack surface for existing supply chain threats, what slopsquatting is and why it's purpose-built for AI assistants, and why agentic tools remove the one moment human review used to provide.
What they cover:
- Why the rise of AI-generated code is widening the gap between development speed and review quality
- What slopsquatting is: how attackers pre-register packages that match names AI models are likely to hallucinate
- How cooldown policies and malicious package detection close the window slopsquatting exploits
- Why agentic systems need explicit guardrails to prevent pulling dependencies directly from public registries
- Why registry-level controls matter more, not less, as AI takes on more autonomous tasks in the development workflow
0:00 - AI-generated code and the review gap
1:21 - What is slopsquatting?
1:55 - How slopsquatting differs from typosquatting
2:24 - Registry-level defenses: cool-down and malicious package policies
2:57 - Agentic AI and the case for private registries
This video covers AI supply chain security, slopsquatting, agentic AI risk, software dependency management, open source security, and registry-level controls for DevSecOps and platform engineering teams using GitHub Copilot, Cursor, or similar tools.
Book a demo to see how Cloudsmith helps govern your software supply chain: https://cloudsmith.com/book-a-demo
Subscribe for more on software supply chain security, artifact management, and open source risk.
#SoftwareSupplyChain #DevSecOps #Cloudsmith #AISecurityRisks