AI Coding Tools Introduce Open-Source Supply Chain Risks

TL;DR. AI coding assistants accelerate software supply chain vulnerabilities by suggesting unvetted or hallucinated open-source dependencies at machine speed. - LLMs recommend package names based on statistical probability, not real-time registry verification, creating 'slopsquatting' opportunities. - Attackers register hallucinated package names with malicious payloads, exploiting automated developer environments. - Securing the pipeline requires governing packages at the point of selection, before they enter development builds.

Sources

Back to QLANKR News