What this means for your agents and systems:
TL;DR
AI coding agents are hallucinating package names that don't exist—and attackers are registering them on npm and PyPI to capture the traffic. One researcher demonstrated this by registering a fake react-codeshift package…