Open source maintainers are right to be concerned about AI slop, but banning AI-generated code outright is a huge mistake.
JFrog found malicious npm packages that deploy a Windows RAT to steal Chrome credentials, run commands, and transfer files.