secure-coding-package-hallucination-rate-gpt-4
observationsingle paper

GPT-4 recommended non-existent Python and JavaScript packages in only a small percentage of generations — lower than the open models tested in the same study — but the same hallucinated names recurred often enough across runs to be practically exploitable by an attacker who registers them ahead of time.

Capability: Writing secure code and dependencies

Observed on

GPT. 2024, GPT-4 class. Coding agent.

Sources

Status: activeLast checked: 2026-09-03Evidence activityHow much the field cites the sources under this claimheavily cited in the last 12 months80 in 12mo · 106 total — We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
Contest this claim

Disagreeing is the most useful thing you can do here. Both sides of every contested claim in this catalog were assembled by the same person, which is its weakest point.

Related claims