
I Asked Claude for a Package. It Didn't Exist. An Attacker Had Already Registered It.
AI models recommend packages that don't exist. Attackers register them. Your npm install becomes the attack. Learn how hallucinated dependencies work and how to protect your codebase.