PhantomRaven is a campaign that registered fake npm package names hallucinated by AI coding tools. It hid malware in 126 npm packages, achieving over 86,000 installs. This highlights the risk of slopsquatting, where attackers exploit AI-generated software dependencies.