Hallucinated Package Dependencies
AI assistants frequently reference packages that do not exist. Attackers register these phantom package names on npm, PyPI and RubyGems, then wait for developers to install them. A single npm install of a hallucinated dependency can deliver malware directly into your build pipeline. This is not theoretical. Researchers have documented thousands of hallucinated package names from popular AI assistants and confirmed that attackers actively exploit this vector.