AI coding agents are installing packages no one owns
AI coding agents are installing npm packages that don't exist, creating "package hallucinations." Attackers can register these fake package names on public repositories to distribute malware, while developers lack standard tools to detect such automatic installations.