404
AI bots hallucinate software packages and devs download them
(www.theregister.com)
This is a most excellent place for technology news and articles.
The official repositories often have no useful oversight either. At least once a year, you'll hear about a malicious package in npm or PyPI getting widespread enough to cause real havoc. Typosquatting runs rampant, and formerly reputable packages end up in the hands of scammers when their original devs try to find someone to hand them over to.