"All that's required is to create a malicious software package under a hallucinated package name and then upload the bad package to a package registry or index like PyPI or npm for distribution".
I'm not going to comment because I'm sure many people will get offended by my comments 😈
https://www.theregister.com/2025/04/12/ai_code_suggestions_sabotage_supply_chain/