When AI coding agents hallucinate package names, attackers register those exact names with malicious payloads. Here is the complete attacker playbook for slopsquatting: how they identify targets, register packages, and why AI agents make better victims than humans ever were.