Slopsquatting: AI Hallucinations Fuel New Class of Supply Chain Attacks
socket.dev
socket.dev
Note also that this article climaxes with a "by the way, did you know our product solves this issue...?" ad.
Running AI coding setups in containers (or even just VMs) seems like a solid default, and I’d love to see tooling move in that direction by default—less as a hard security perimeter, more as a safety net for people trying to move fast.
Re: the article’s conclusion—I get the skepticism. For what it’s worth, the product came after years of trying to solve the problem of package security and maintainer funding in the open. At some point, it felt like the best way to make a dent was to build something dedicated to it.