USENIX Security 2025 researchers found 19.7% of packages suggested by 16 LLMs were fake, and 43% of those names recurred on every re-run. Names that repeat can be registered ahead of time, so a team has to vet a suggested dependency before installing it, even when the install succeeds.
Reality
- Evidence58
- Adoption20
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
UMass Amherst researchers bought groceries with an expired contactless card. The date that is supposed to kill it is unsigned, zeroed out before the issuer sees it, and checked by nobody in particular.
Perspective Coverage
5 publishers
- Builder
- Builder 42%
- Operator
- Operator 51%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence70
CSAIL researchers timed an interrupt to land inside the gap AMD's saferet defense leaves open, then pulled the root password file off a current Linux kernel. AMD has shipped a mitigation. Intel's picture is messier.
Reality
- Evidence38
- Adoption30
- Hype gap+26
- Incentives55
- Confidence44
Academics rebuilt Tiangou Secure Gateway firmware from leaked Git history and matched its filtering to the Great Firewall. One of three DNS injectors matched, and that ratio is the interesting part.
Reality
- Evidence68
- Adoption66
- Hype gap+8
- Incentives42
- Confidence58
Academics rebuilt Geedge Networks' Tiangou Secure Gateway firmware from a 100,000-file leak and matched its filtering to China's censorship system. The same box has been exported.
Reality
- Evidence66
- Adoption68
- Hype gap+12
- Incentives32
- Confidence58
A vendor essay on AI package hallucination makes a defensible case: a package name that does not exist yet cannot be scanned, so the control has to sit at selection.
Reality
- Evidence24
- Adoption22
- Hype gap+41
- Incentives88
- Confidence45