dep-verify-guard
dep-verify-guard
Never install a package on faith. LLMs predictably hallucinate
plausible-sounding package names, and attackers pre-register those exact
names on public registries so the hallucination becomes a working,
malicious install the moment an agent runs npm install <name>. This
guard makes "does this package actually exist, and do we actually need
it" a checked step, not an assumption.
Research on this failure mode (CSA, Unit42, and related slopsquatting
studies) found that LLM code generation hallucinates non-existent package
names in a meaningful fraction of dependency-adding requests, and that a
large fraction recur (reported in 2025–2026 slopsquatting research) across
repeated runs of the same prompt — stable enough for an attacker to
pre-register the exact name and wait. react-codeshift is a plausible
example of the pattern: a name an LLM could plausibly produce by
conflating two real packages (jscodeshift + react-codemod), but it does
not exist as a real published package. This guard exists to catch that
pattern before npm install runs, not after.