How Stateward protects you against typosquatting & slopsquatted packages
The threat
Attackers publish packages one keystroke away from a popular name, and AI assistants confidently import dependencies that don’t exist, "slopsquatting", which attackers then register and weaponise.
How Stateward catches it
Stateward’s supply-chain engine flags names within typo-distance of a popular package, packages that don’t exist on the registry (hallucinated/slopsquatted), and non-registry sources (git+, file:, http:), then analyzes each added package’s published behavior: install/postinstall hooks that run network/exec/obfuscated code, or install code with no source repository, the dependency-confusion malware shape that CVE databases miss.
Recent advisories of this class
- highGHSA-7q9c-hpx7-9cwmTypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- criticalCVE-2026-73842OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- mediumCVE-2026-73557 vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
- mediumCVE-2026-73556vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Check your own repo for this
Connect a repo and Stateward reviews your next pull request, read-only, free for individuals and open source.
Built to be trusted with your code
Read-only & ephemeral
Stateward can comment, but never pushes, merges or stores your keys.
EU hosting & data residency
Code and security data stay EU-hosted with EU data residency, built for NIS2, DORA and the CRA.
Whole-codebase aware
Reasons over your call graph and trust boundaries, not just the diff.
Stateward is live and ready to guard your code. Built by Yggdrasil Digital.