Multiple top AI coding tools have been found to consistently generate the same 127 fake PyPl and npm package names, creating an opportunity for hackers to exploit this phenomenon through slopsquatting attacks. This type of attack involves the creation of malicious packages with names that match those hallucinated by AI coding tools, putting enterprise software developers at risk. Researcher Aleksandr Churilov discovered this consistency across five different large language models (LLMs)1, highlighting the potential for widespread vulnerability. The fact that these AI tools are generating identical fake package names suggests a lack of diversity in their training data or algorithms. This consistency enables hackers to anticipate and prepare malicious packages, making it easier to carry out slopsquatting attacks. As a result, practitioners should be cautious when relying on AI coding tools and verify the existence of packages before using them, to avoid falling prey to these types of attacks.