Join our Newsletter — 33% off our NHI Course

AI package hallucinations: what security teams need to do now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Large language models still recommend nonexistent packages at material rates, with 24.2% hallucinations in GPT-4, 22.2% in GPT-3.5, 64.5% in Gemini, and 29.1% in Cohere across 47,803 how-to prompts, according to Lasso Security research. The risk is not just bad answers, but a poisoned dependency path that security and engineering teams must validate before code reaches production.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Diving Deeper into AI Package Hallucinations”.

Key questions

Q: How should security teams handle AI-suggested packages before they reach production?

A: Treat AI-generated dependency names as untrusted input.

Q: Why do hallucinated packages create supply-chain risk even when the model is not directly compromised?

A: Because the attacker does not need to break the model to exploit the output.

Q: What signs show that AI package hallucinations are becoming a governance problem?

A: Watch for repeated false package names across teams, developers copy-pasting model output into installs, and dependency approvals based on search results instead of registry evidence.

Practitioner guidance

  • Validate every AI-suggested dependency Check package existence, maintainer identity, release history, and repository activity before allowing a suggested library into code or build pipelines.
  • Block unapproved package names at the gateway Use dependency proxies, internal allowlists, and build policy to stop invented or squatted names before installation is attempted.
  • Track recurring hallucinated package names Log repeated false suggestions from LLM workflows and feed them into threat intelligence, code review, and developer guidance.

Bottom line: AI package hallucinations turn model output into a supply-chain intake problem when developers trust invented dependency names.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

AI package hallucination is a supply-chain trust failure, not a content-quality bug. The article shows that model output can create false dependencies that developers may search for, install, or document. That shifts the attack surface from language generation into software acquisition and build-time trust. The practitioner implication is simple: any AI-suggested package must be treated as untrusted until provenance is independently confirmed.

A few things that frame the scale:

  • 52 real-world breaches show that identity failures become exploitable when trust is granted before provenance is verified, according to The 52 NHI breaches Report.
  • In our research, supply-chain and secret exposure patterns recur across many incidents, which is why package validation must be treated as a governance control, not a developer preference.

A question worth separating out:

Q: What should organisations do before allowing AI-generated dependencies into production?

A: They should require a controlled approval workflow that checks package existence, maintainer identity, signature or checksum, and vulnerability history. That workflow should sit between model output and installation so an invented package cannot move directly into production tooling or release pipelines.

👉 Read our full editorial: AI package hallucinations are creating a new supply-chain risk



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

AI package hallucinations are a software supply-chain control failure, not just a model-quality issue. The real risk starts when developers treat a model answer as a dependency recommendation and skip normal provenance checks. That shifts the problem from prompt reliability into package intake governance, where repository existence, ownership, and maintenance history should already be verified. The implication is that AI-assisted development needs dependency validation as a control boundary, not a courtesy review.

A few things that frame the scale:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: What should organisations do before allowing AI-generated dependencies into production?

A: They should require a controlled approval workflow that checks package existence, maintainer identity, signature or checksum, and vulnerability history. That workflow should sit between model output and installation so an invented package cannot move directly into production tooling or release pipelines.

👉 Read our full editorial: AI package hallucinations are creating a new supply-chain risk


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.