Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Code-generating AI can invent software package names, creating a path for attackers to publish malicious packages under those names and target developers who install them without checking. The underlying package-confusion tactic is not new; using AI-generated names as a discovery route is the newer risk. A 2025 study measured hallucinated package references in selected models and prompts, but did not measure real-world compromises or establish current 2026 prevalence.

What is a package hallucination?

A package hallucination occurs when generated code recommends or refers to a package that does not exist in the relevant software repository at the time of checking. In the words of study authors Joseph Spracklen and colleagues, “Package hallucination occurs when an LLM generates code that recommends or contains a reference to a package that does not actually exist.”

The risk is not limited to code that fails to run. If an invented name sounds plausible, someone could publish a package under that name in the relevant registry. A developer who later installs the AI recommendation may then install attacker-controlled code. Package installation can execute code, and malicious dependencies can also affect downstream projects that rely on them.

Why is this a security risk?

The attack combines package confusion with an AI-generated lead. Typosquatting and other attempts to mislead people about package names predate coding assistants. The distinct element is that an attacker can ask the same or a similar model for code, collect names it invents, and register matching names in a package registry. Spracklen et al. describe this attack path; their own study did not publish malicious packages using the hallucinated names, citing ethical concerns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That distinction matters: the study establishes that package hallucinations occur in its tested setup and explains how an attacker could exploit them. It does not report a count or rate of real-world compromises caused by this attack.

What did the 2025 study find?

Spracklen and colleagues, affiliated with the University of Texas at San Antonio, the University of Oklahoma, and Virginia Tech, analyzed 576,000 generated code samples across Python and JavaScript. Their study examined 16 code-generating LLMs using two prompt datasets, including real Stack Overflow questions and prompts derived from package descriptions.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Hallucinated-package rates: The study reported average rates of at least 5.2% for commercial models and 21.7% for open-source models in the tested setup. Results varied substantially by model and language.
  • Distinct examples: The authors reported 205,474 unique hallucinated package-name examples.
  • Scope: These are experimental results for the study’s models and prompts, not estimates of how often all developers receive or install a bogus dependency.

The authors’ analysis does not establish the precise causes of hallucinations. They also note that newer, more advanced models appeared after their work, so the findings should not be treated as a measure of current 2026 production behavior.

How do I check whether an AI-suggested package is real and safe?

  1. Confirm the exact name and ecosystem. Search the official registry for the package in the language or ecosystem the code uses, and check the project’s authoritative documentation for the intended dependency. Watch for small spelling differences and similarly named packages.
  2. Verify that the project actually recommends it. A package’s presence in a registry proves only that it has been published, not that it is the package the project intends you to use or that it is trustworthy.
  3. Review the package and its provenance. Check the maintainer, linked source repository, version history, and whether the package’s purpose and activity make sense for the code. Treat an unexplained or newly appearing dependency cautiously.
  4. Use your normal supply-chain controls before installation. Apply your project’s established dependency review, scanning, and installation policies. Do not bypass them because a model supplied a convincing explanation or working-looking code.

The key trap is relying on an existence check alone: if an attacker has already registered the hallucinated name, the package will appear in the registry. Verification must establish that it is the intended, trustworthy dependency, not merely that some package with that name exists.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Can changing model settings prevent false packages?

In the tested models, higher temperature increased hallucinations, while lower temperature reduced them; the effect varied by model, and less varied output can mean less creative output. The study found that its tested decoding-parameter changes did not provide a reliable reduction. A lower-temperature setting can therefore be a secondary precaution, not a substitute for checking dependencies.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What mitigations did researchers test?

The paper evaluated four approaches in DeepSeek Coder 6.7B and CodeLlama 7B setups. All reduced hallucinations in those tests, but the results are model-specific and do not establish effectiveness across deployed systems.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Approach How it works Study result and trade-off
Retrieval-augmented generation Supplies valid package names to the model during generation. Reduced hallucinations in the evaluated setups. Requires a source of package-name information and does not, by itself, prove that a retrieved package is trustworthy.
Self-refinement Has the model review or revise its output after generation. Reduced hallucinations in the evaluated setups; the paper does not establish a universal reduction for other models or deployments.
Supervised fine-tuning Further trains a model using curated examples. Performed especially well in the evaluated tests, but also reduced benchmark code quality.
Ensemble of methods Combines mitigation approaches. Performed especially well in the evaluated tests; its performance remains specific to the studied models and setup.

These techniques are potential model-side defenses, not a reason for developers to skip dependency review. The study’s strongest reported mitigation results came with trade-offs or setup-specific evidence, rather than a cost-free guarantee.

How should developers interpret the risk?

False package suggestions are a credible software supply-chain risk, but the evidence supports a precise conclusion: selected models produced invented package references in a controlled study, and attackers could use those names in a package-confusion attack. It does not support a claim that a quantified number of real-world incidents has occurred, nor a current industry-wide hallucination rate. For developers, the practical response is straightforward: treat AI-generated dependencies as unverified input and establish that each one is the intended, trustworthy package before installing it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: Spracklen et al., “We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs,” arXiv version 3, March 2, 2025; Tyler August, Hackaday, April 12, 2025.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.