Nigel Douglas - How can we abuse AI hallucinations to feed the already bloated software supply chain
About this talk
This talk delves into the emerging threat of slopsquatting, a risk associated with generative AI that exploits its tendency to produce non-existent software packages from public repositories like PyPi and DockerHub. The speaker examines how hackers can leverage these “phantom” packages to distribute malware, effectively turning AI-generated errors into opportunities for supply chain compromises. The session includes a live demonstration of the slopsquatting attack chain and offers strategies for organizations to defend against this sophisticated threat. Understanding these risks is crucial for tech teams that rely on public upstreams in their build pipelines.