A study found 227 install commands in corporate docs pointing to unowned code, affecting Claude, Codex, and Hermes users. The commands likely came from AI assistant outputs and can expose developers to supply chain attacks. Developers should verify package ownership before running AI-suggested installs.
Opening Kapyn…