Every npm supply chain postmortem ends with the same advice: verify the package before you install it.
So I looked at what the tools that do this actually check. Most of them check whether the package exists.
That check is dead. Here are three package names documented as AI hallucinations, against the npm registry right now:
react-codeshift HTTP 200
react-fetch-hook HTTP 200






