TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Slopsquatting: AI Hallucinations Fuel New Class of Supply Chain Attacks

12 点作者 adriand大约 1 个月前

1 comment

sabslikesobs大约 1 个月前
I saw this in action when a friend was live-streaming while vibe coding in Javascript. He noted that dozens of unknown npm packages were installed and running unchecked on his computer (without any containerization, no less). Encouraging AI coding in containers, or with different languages, would help, but Javascript probably has the most available content.<p>Note also that this article climaxes with a &quot;by the way, did you know our product solves this issue...?&quot; ad.
评论 #43665409 未加载