Securing The Build: The AI-Generated Dependency Problem

Daniel Wyrzykowski June 11, 2026

How AI-generated dependencies create new software supply chain risks.

Generative AI is quietly reshaping the software supply chain, and not for the better. In this episode we break down slopsquatting, where attackers register AI-hallucinated package names on npm and PyPI to slip malicious code into your builds, plus the poisoned blogs, Stack Overflow answers, and docs that feed bad data straight into AI training sets and RAG pipelines. We also dig into glitch tokens and glitch frames that can push text and multimodal models into erratic, exploitable behavior. If you build with AI, these are the new attack surfaces traditional supply chain defenses were never designed to catch.

Speakers:

  • Daniel Wyrzykowski, Product Manager – Mend.io
  • Paul John Spaulding, GM, Production – Cybercrime Magazine