HalluSquatting is a supply-chain attack: an attacker registers a package that doesn't exist but that your AI coding agent hallucinates and recommends. When the agent installs it, it downloads the malicious package already waiting under that exact name.
01
Why human code review doesn't catch this
02
How to protect your pipeline without buying a full SCA suite
We review your dependency pipeline and set up quarantine gates before a hallucinated package reaches production.
Solicitar diagnóstico