Security9 min read
The hallucinated dependency attack: a new supply chain surface AI created
AI coding agents hallucinate package names. Attackers now publish those names as malicious packages and wait for the install. Three pre-install checks block the attack.