Inside the npm Supply-Chain Attacks Targeting AI Coding ToolsThe slopsquatting threat. An investigation into DPRK-linked npm attacks, AI hallucinated package names, and self-replicating worms compromising CI/CD pipelines.8/1/202623 min read