The package doesn't exist
Confident code importing something entirely fictional.
The symptom
The code looks right. You install the dependency and it 404s, or you import the function and it isn't there. The documentation the model described doesn't exist anywhere.
What's happening
Models generate plausible text, and a plausible package name is easy to generate. Names that sound like they should exist, functions that should be on that object, config options that would make sense — all produced with the same confidence as real ones.
This gets worse for newer or more niche libraries, and for anything that changed its API recently.
The fix
Check before you build on it:
Before I run this, audit your own answer. List every package, module, function, method and config option you used that I didn't write. For each: - Does it exist, and is it still the current way to do this? - Which version are you assuming? - How confident are you, honestly? Flag anything you're less than certain about. I'd rather have "I'm not sure" than a name that 404s.
Then check the flagged ones against the actual registry or documentation. Thirty seconds each.
The dangerous version
Attackers watch for commonly hallucinated package names and register them with malicious code inside. Installing a package because a model suggested it, without checking it's the real thing, is a genuine supply-chain risk.
Check the download count, the repository link and the publish date before installing anything unfamiliar.
If a library is central to what you're building, read its actual documentation once. Models are far more reliable about libraries you can then correct them on.