Opening SecureFlowChatGPT Package Hallucination
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0022

ChatGPT Package Hallucination

  • AI Supply Chain
  • System Compromise & RCE

Researchers identified that large language models such as ChatGPT can hallucinate fake software package names that are not published to a package repository. An attacker could publish a malicious package under the hallucinated name to a package repository. Then users of the same or similar large language models may encounter the same hallucination and ultimately download and execute the malicious package leading to a variety of potential harms.

Mapped threat techniques

Source

Updated