Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
80 512d 17 28 ↑0.0/day SUSPICIOUS google pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-events-google-pubsub/
Matched naming pattern: django-google-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-events-google-pubsub' matches AI hallucination template [django] + [google] + [auth].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 512d 16 28 ↑0.0/day SUSPICIOUS vllm pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-runtimes-vllm/
Matched naming pattern: corex-vllm-runtimes
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 16/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-runtimes-vllm' matches AI hallucination template [corex] + [vllm] + [runtimes].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 511d 13 28 ↑0.0/day SUSPICIOUS azure pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-storage-azure-blob/
Matched naming pattern: corex-azure-azure
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 511
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-storage-azure-blob' matches AI hallucination template [corex] + [azure] + [azure].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 16 28 ↑0.0/day SUSPICIOUS auth0 pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-security-auth0/
Matched naming pattern: corex-auth0-auth0
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 16/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-security-auth0' matches AI hallucination template [corex] + [auth0] + [auth0].
  • HIGHClaims critical enterprise brand identity ('AUTH0').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 21 28 ↑0.0/day SUSPICIOUS openai pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-nlp-openai/
Matched naming pattern: corex-openai-nlp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 21/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-nlp-openai' matches AI hallucination template [corex] + [openai] + [nlp].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 17 28 ↑0.0/day SUSPICIOUS huggingface pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-nlp-huggingface/
Matched naming pattern: corex-huggingface-nlp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-nlp-huggingface' matches AI hallucination template [corex] + [huggingface] + [nlp].
  • HIGHClaims critical enterprise brand identity ('HUGGINGFACE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 18 28 ↑0.0/day SUSPICIOUS llama pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-nlp-llama/
Matched naming pattern: corex-llama-nlp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 18/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-nlp-llama' matches AI hallucination template [corex] + [llama] + [nlp].
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 0 28 ↑0.0/day SUSPICIOUS mistral pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-nlp-mistral/
Matched naming pattern: corex-mistral-nlp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-nlp-mistral' matches AI hallucination template [corex] + [mistral] + [nlp].
  • HIGHClaims critical enterprise brand identity ('MISTRAL').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 0 28 ↑0.0/day SUSPICIOUS cohere pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-nlp-cohere/
Matched naming pattern: corex-cohere-nlp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-nlp-cohere' matches AI hallucination template [corex] + [cohere] + [nlp].
  • HIGHClaims critical enterprise brand identity ('COHERE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 22 28 ↑0.0/day SUSPICIOUS weaviate pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-embeddings-weaviate/
Matched naming pattern: corex-weaviate-embeddings
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 22/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-embeddings-weaviate' matches AI hallucination template [corex] + [weaviate] + [embeddings].
  • HIGHClaims critical enterprise brand identity ('WEAVIATE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 18 28 ↑0.0/day SUSPICIOUS llama pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-retrieval-llama-index/
Matched naming pattern: corex-llama-retrieval
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 18/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-retrieval-llama-index' matches AI hallucination template [corex] + [llama] + [retrieval].
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 17 28 ↑0.0/day SUSPICIOUS qdrant pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-retrieval-qdrant/
Matched naming pattern: corex-qdrant-retrieval
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-retrieval-qdrant' matches AI hallucination template [corex] + [qdrant] + [retrieval].
  • HIGHClaims critical enterprise brand identity ('QDRANT').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 12 28 ↑0.0/day SUSPICIOUS pinecone pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-retrieval-pinecone/
Matched naming pattern: corex-pinecone-retrieval
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 12/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.1 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-retrieval-pinecone' matches AI hallucination template [corex] + [pinecone] + [retrieval].
  • HIGHClaims critical enterprise brand identity ('PINECONE').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 512d 20 28 ↑0.0/day SUSPICIOUS ollama pypi 0.1.0 Jochen Schultz js@intelligent-intern.com intelligent-intern.com
Claimed homepage: https://pypi.org/project/corex-ai-runtimes-ollama/
Matched naming pattern: corex-ollama-runtimes
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 512
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 20/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.0 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'corex-ai-runtimes-ollama' matches AI hallucination template [corex] + [ollama] + [runtimes].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'js@intelligent-intern.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD