There's a category of supply-chain attack that only exists because of AI coding agents, and it has
one of the better names in security: slopsquatting.
The mechanic takes one paragraph to explain. Large language models hallucinate package names. Not
randomly — consistently. Ask enough models to scaffold a FastAPI service and a measurable fraction
will import helper packages that don't exist, and the same phantom names recur across models and














