Assertion Supported AI assessment confidence: 95% certainty 4/5 debate potential 2/5

Aboukhadijeh: Rival frontier models share universal hallucinations for non-existent software packages

Feross Aboukhadijeh · AI Is Learning to Hack. Faster Than We Expected. · Aug 6, 2026 · at 4:06

Feross Aboukhadijeh, CEO of Socket, discusses how AI models create supply chain vulnerabilities by recommending package names that do not exist, exposing developers to typosquat attacks.

0:00 / 0:20exact quote · 20.7s
▶ Watch the full episode on YouTube → 720p mp4 · rendered on demand · StarZero watermark
“There was a research published recently about what they're calling kind of like universal type of squats or universal hallucinations where all the frontier models all have the same make the same mistake and sort of assume there are certain packages that exist that don't despite like the, those models coming from different companies.”

quote is from the automated transcript, cleaned for reading: filler sounds and stutters are removed, nothing is rephrased. names can be misheard (the analysis reads context, assessments check outside sources). how →

More from Feross Aboukhadijeh

Assertion Not checkable as stated
Aboukhadijeh: Frontier AI Models Drastically Shrink Time to Exploit Vulnerabilities
“The frontier models are gonna cause, you know, a, you know, they are causing kind of a massive reduction in the time between the vulnerability discovery and vulnerability exploitation.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 7:50 AI Is Learning to Hack. Faster Than We Expected.
Assertion Not checkable as stated
Aboukhadijeh: AI prompt payloads evade traditional endpoint detection and response tools
“A lot of times the payloads are actually prompts and that, that bypasses a lot of you know, typical kind of EDR tooling, because, you know, it's just like a markdown file that your cloud is running.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 14:36 AI Is Learning to Hack. Faster Than We Expected.
Insight
Aboukhadijeh: Unvetted public package registries are the easiest targets for attackers
“They're gonna pick the easiest way in, and the lowest hanging fruit now has become, you know, just publishing malware to public registries because they know that there's no vetting happening and, you know, developers are likely to install them.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 3:52 AI Is Learning to Hack. Faster Than We Expected.
Assertion Supported
Aboukhadijeh: Threat Actors Open-Sourced a Vibe-Coded NPM Malware Toolkit
“One of the threat groups actually kind of posted their, you know, open source to their kind of vibe coded toolkit for others to use to be able to do this. You know, we've seen copycat attacks happen since then.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 13:56 AI Is Learning to Hack. Faster Than We Expected.
Assertion Not checkable as stated
Aboukhadijeh: Attackers Time NPM Worms for RSA and Black Hat
“I noticed the attackers seemed to pick RSA and Black Hat as the times they wanted to start these NPM worms.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 21:14 AI Is Learning to Hack. Faster Than We Expected.
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.