Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

Software ecosystems

Incidents Harmed By

Incident 7314 Report
Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

2023-12-01

Large language models have reportedly hallucinated non-existent software package names, some of which were subsequently uploaded to public repositories and incorporated into real codebases. In one case, a package named huggingface-cli, which was purported to have been originally suggested by an AI model, was downloaded more than 15,000 times. This dynamic enables what security researchers have termed "slopsquatting," in which attackers register hallucinated package names and introduce potential malware into software supply chains.

More

Incidents implicated systems

Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

2026-07-26

Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Developers using AI-generated suggestions

Incidents involved as Deployer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Bar Lanyado

Incidents involved as Deployer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

OpenAI

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Meta

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Google

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

DeepSeek AI

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Cohere

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

BigScience

Incidents involved as Developer
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Users downstream of software contaminated by hallucinated packages

Incidents Harmed By
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Trust in open-source repositories and AI-assisted coding tools

Incidents Harmed By
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Organizations that incorporated fake dependencies

Incidents Harmed By
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Developers and businesses incorporating AI-suggested packages

Incidents Harmed By
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Alibaba

Incidents Harmed By
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Python Package Index (PyPI)

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

npm (Node.js)

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

LLM-powered coding assistants

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

LLaMA

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Google Search / AI Overview

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

GitHub

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Gemini Pro

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

DeepSeek Coder

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Command

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

CodeLlama

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

BLOOM

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

GPT-4

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

GPT-3.5

Incidents implicated systems
  • Incident 731
    4 Reports

    Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers

More
Entity

Government agencies

Incidents involved as Deployer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

AI Security Institute (United Kingdom)

Incidents involved as Deployer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

AI evaluation organizations

Incidents involved as Deployer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Anthropic

Incidents involved as Developer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Software developers

Incidents Harmed By
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Open-source maintainers

Incidents Harmed By
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

GitHub users

Incidents Harmed By
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Supply chains

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Large language models

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

GPT-5.6 Sol

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

GitHub repositories

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Claude Mythos 5

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

Claude

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1633
    4 Reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754