Slopsquatting
Models invent plausible-but-fake package names — blending eslint and a
router into eslint-fast-router. Attackers pre-register those names on npm
and PyPI, turning a hallucination into a supply-chain attack. Hipper
checks every proposed package against the live registry and halts the install.