Supply chain
Hallucinated package
A hallucinated package is a package name a code-generating model writes into an import or install line although no such package exists in the registry.
What it means
A hallucinated package is a model error. A code-generating model writes an import or install line whose name belongs to no package in the registry.
In Spracklen et al.’s USENIX Security 2025 study, 16 models produced 576,000 Python and JavaScript samples; 19.7% of the 2.23 million package references in them were hallucinations, spanning 205,474 unique invented names. Commercial models averaged at least 5.2%, open-source models 21.7%.
Four neighboring terms mean something else:
- Slopsquatting registers a name models keep inventing; the hallucination comes first.
- Typosquatting exploits a mistyped name, not an invented one.
- Phantom dependency is a real package used without being declared.
- Dependency confusion is a public package published under a private package’s name so the resolver prefers it.
How it works
An invented name reaches the registry in three steps:
- The model writes the name. It comes from gaps in the training data, not a registry lookup, and the model knows nothing published after its cutoff. Most invented names are not typos of real ones, and the rate climbs with sampling temperature.
- Someone runs the line. A developer pastes it, or an agent executes it as part of its task.
- The registry answers in one of two ways: nothing is there and the install fails, or an attacker has already published under the name, which is slopsquatting. A wrong but existing name is a different error, one the study does not count.
Names recur: in the same study a hallucinated package was repeated more than once in ten iterations 58% of the time, and 43% came back in all ten queries. A name that returns every time is the one worth registering in advance.
Why it matters for AI-written code
In June 2023 Bar Lanyado, then at Vulcan Cyber, had ChatGPT recommend packages not published in any legitimate registry and named the technique AI package hallucination.
By 2024, at Lasso Security, he had uploaded an empty package under a name models kept producing, huggingface-cli, while the real tool ships inside huggingface_hub. By his count it drew more than 30,000 downloads in three months and reached an Alibaba research repository’s README.
Newer models have not retired the error: a 2026 replication on five frontier models measured rates between 4.62% and 6.10% and found 127 names that all five invented identically.
OpenSSF’s guide for AI code assistant instructions makes the same point from the assistant’s side: no dependency that may be malicious or hallucinated, and installs through the official package manager instead of copied snippets. OWASP’s Top 10 for LLM Applications 2025 files a model suggesting insecure or non-existent code libraries under LLM09, Misinformation.
How Enji Guard helps
No Enji Guard audit checks whether a package name is real; the dependency hygiene audit records what stands between an install line and the registry.
Its inventory covers the files an install line touches: manifest, lockfile, Dockerfile, CI workflow, install script. For each install path it records:
- whether installs run in frozen or locked mode and use the lockfile;
- whether a package-age gate, quarantine, or private mirror sits in front of the registry;
- whether lifecycle scripts are controlled.
Two of the nine criteria cover this case: reproducible install, and safe install and acquisition paths. A missing lockfile or frozen mode without proven privileged exposure is rated medium; a non-reproducible primary CI, build, or release install path caps the score at 69. The finding names the path and the gap, for example npm install in CI without a frozen lockfile.
The audit does not compare a package name with a registry, decide whether a package is real, or block an install. It is read-only and changes neither manifest nor lockfile; the right name is the reviewer’s call.
The next run confirms a lockfile added after the finding as reproducible-install evidence. The dependency updates improvement takes one dependency root cause with a proven safe target version; an invented name has none.
Enji Guard