AI Slopsquatting & Package Hallucination Checker
LLMs often hallucinate package names that sound plausible but don't exist. Attackers register these phantom names with malicious code ("slopsquatting") waiting for developers to npm install them. Paste your dependencies below to verify them against the live npm registry.
package.json or package namesHow Slopsquatting Works
When an AI coding tool like Cursor, Bolt, or Claude writes a component, it might invent a package like next-auth-supabase-adapter-v2. If that package doesn't exist today, an attacker can register it tomorrow with malicious postinstall scripts.
The next time you or your team run a clean install in CI/CD, the attacker's script executes and exfiltrates your process.env secrets to an external server.
Ready to Audit Dependencies
Click the button on the left to verify your packages against the official npm registry. We check each package for 404 status and dangerous wildcard versions.
The Founder Pass ($15 one-time) analyzes your transitive dependencies, package lockfiles, GitHub Actions, and 106 other launch criteria in minutes.