Home/Tools/AI Slopsquatting & Package Checker
100% Free Developer Utility

AI Slopsquatting & Package Hallucination Checker

LLMs often hallucinate package names that sound plausible but don't exist. Attackers register these phantom names with malicious code ("slopsquatting") waiting for developers to npm install them. Paste your dependencies below to verify them against the live npm registry.

Paste package.json or package names

How Slopsquatting Works

When an AI coding tool like Cursor, Bolt, or Claude writes a component, it might invent a package like next-auth-supabase-adapter-v2. If that package doesn't exist today, an attacker can register it tomorrow with malicious postinstall scripts.

The next time you or your team run a clean install in CI/CD, the attacker's script executes and exfiltrates your process.env secrets to an external server.

Ready to Audit Dependencies

Click the button on the left to verify your packages against the official npm registry. We check each package for 404 status and dangerous wildcard versions.

Want deep supply chain and lockfile analysis?

The Founder Pass ($15 one-time) analyzes your transitive dependencies, package lockfiles, GitHub Actions, and 106 other launch criteria in minutes.