This is the practice of registering fake packages, that only LLM coding agents believe are true. Attacker sets up malware on a package repository like pip, npm, Gems