AI bots hallucinate software packages and devs download them
Briefly

If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.
Alibaba was referring to it in GraphTranslator's README instructions rather than the real Hugging Face CLI tool.
Read at Theregister
[
]
[
|
]