Four packages below. One of them doesn't exist. Tap the fake.

Your AI just wrote: npm install …

  1. zod

  2. not-real-banana-auth-9000

  3. express

  4. date-fns

Tap Real or Invented for each one. Then we'll show you the only check that actually works.

An AI suggested all four with equal confidence. The invented one is a hallucination: plausible text that isn't true.

Real or invented? (npm, checked 25 Sep 2026)

zod

Status
Real
How to tell
Has an npm page and a linked repo

express

Status
Real
How to tell
Has an npm page and a linked repo

date-fns

Status
Real
How to tell
Has an npm page and a linked repo

not-real-banana-auth-9000

Status
Invented for this lesson (a joke name)
How to tell
No such package on npm when checked. The real test: can you find its page?

Models predict likely-looking text. A package name that sounds right is likely-looking, whether or not anyone ever published it.

It's measurable. A 2024 study generated 576,000 code samples with 16 models and found hallucinated packages averaged "at least 5.2% for commercial models and 21.7% for open-source models."

The danger: the authors call package hallucinations "a novel form of package confusion attack". If an invented name gets registered by someone malicious, the next person told to install it gets their code.

It's showing up in shipped apps. TNW's April 2026 report cites an assessment in which 91.5% of vibe-coded apps had at least one vulnerability traceable to AI hallucination.

Try it with the rules off. In the sandbox, install the invented package anyway, then open its contents. That's the point: whoever registers a hallucinated name decides what's inside.

Check yourself

0/4 got it

Saved on this device only. No account, no streaks.

Next in how the AI thinks: What is a reasoning model?.