SupplySide Briefing
A Monday-morning plain-English briefing for CTOs and heads of engineering at companies whose dev teams use AI coding tools — telling non-technical leadership which hallucinated package names were installed last week and what to ask the dev team about, no AppSec hire required.
CTOs, heads of engineering, and product leaders at 20–200 person companies where developers use GitHub Copilot, Cursor, or Claude Code
- One-page weekly executive briefing in plain English with severity ratings
- 'Questions to ask your dev team' talking points drafted for non-technical managers
- Vendor-software audit showing which of your shipped products depend on AI-suggested packages
- Insurance- and board-ready compliance log of every flagged install
A USENIX 2025 study found 19.7% of AI-recommended packages do not exist and one experiment registered a fake 'huggingface-cli' package that pulled 15,000 real downloads — SMBs without AppSec teams are exposed and cannot read the research themselves.
Slopsquatting is widely covered in 2025 (CSA research note, Socket, cybersecuritynews) with multiple 'what businesses need to know' pieces, but SMB/CTO-level buyer awareness remains nascent — not yet a must-buy line item.Slopsquatting: AI Code Hallucinations Fuel Supply Chain Attacks ↗New HalluSquatting Attack Allow Hackers to Poison AI Coding Assistants ↗
Socket, Snyk and Aikido already serve dependency-scanning use cases for engineering teams, but the plain-English Monday-briefing format aimed at non-technical CTOs is a distinct positioning; still, adjacent newsletters (tl;dr sec etc.) cover the raw material free.The Rise of Slopsquatting: How AI Hallucinations Are Fueling... - Socket ↗Aikido vs Snyk: Developer Security Platforms Compared (2026) ↗
Comparable B2B security newsletters monetize at roughly $10–50/month or per-seat, but SMB software buyers are price-sensitive and much of the underlying news is already freely available from Socket/CSA/Snyk blogs, capping willingness-to-pay.Aikido Security vs. Snyk: Comparison & Expert Reviews For 2026 ↗What Is Slopsquatting? AI Packages & Supply Chain Attacks ↗
Hallucinated-package behavior is a structural property of LLMs and AI coding-assistant usage is expanding across SMB engineering teams, so the underlying problem grows rather than fades; no sign of a near-term fix from model vendors.AI Coding Assistant Security Risks: What Teams Must Know ↗Cursor Security Issues in AI Coding Tools and Execution Flows ↗
Detecting which hallucinated names were actually installed at customer sites requires IDE/Copilot telemetry or repo-level scanning that isn't publicly available; building authoritative supply-side intelligence at scale is non-trivial without data partnerships.