Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
5 398d 11 3,004 ↑0.0/day BENIGN_COMMUNITY shopify pypi 0.2.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/shopify-client-oliver/
Matched naming pattern: shopify-shopify-oliver
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 398
Registry downloads: 11/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3004 lines, 100.7 kB across 29 files (LARGE_CODEBASE)
Automated signals flagged:
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (3004 LOC across 29 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
5 857d 11 13 ↑0.0/day BENIGN_COMMUNITY discord pypi 1 mao your@email.com email.com
Claimed homepage: https://github.com/yourusername/discord-control
Matched naming pattern: python-discord-controler
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 857
Code-only verdict: SQUATTED_STUB (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 11/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 13 lines, 380 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • INFOEstablished pre-AI legacy package registered 856 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (13 LOC, 1 file(s), 380 bytes).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
16 190d 23 980 ↑0.1/day BENIGN_COMMUNITY claude pypi 0.1.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/claude-to-whatsapp/
Matched naming pattern: claude-claude-whatsapp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 190
Registry downloads: 23/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 980 lines, 45.1 kB across 22 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-to-whatsapp' matches AI hallucination template [claude] + [claude] + [whatsapp].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 189 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (980 LOC across 22 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
16 245d 12 4,674 ↑0.0/day BENIGN_COMMUNITY azure pypi 1.17.0a1 your@email.com email.com
Claimed homepage: https://pypi.org/project/azure-functions-test/
Matched naming pattern: azure-azure-test
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 245
Registry downloads: 12/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4674 lines, 233.3 kB across 31 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'azure-functions-test' matches AI hallucination template [azure] + [azure] + [test].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 244 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (4674 LOC across 31 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
18 156d 28 2,711 ↑0.2/day BENIGN_COMMUNITY gemini pypi 2.4.12 Your Name your@email.com email.com
Claimed homepage: https://github.com/dsdanielpark/Gemini-API
Matched naming pattern: gemini-gemini-api
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 156
Registry downloads: 28/month, 18/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2711 lines, 114.7 kB across 31 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'gemini-firefox-api' matches AI hallucination template [gemini] + [gemini] + [api].
  • HIGHClaims critical enterprise brand identity ('GEMINI').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (155 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (2711 LOC across 31 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
18 175d 15 2,868 ↑0.1/day BENIGN_COMMUNITY ollama pypi 0.1.1 your@email.com email.com
Claimed homepage: https://pypi.org/project/ollama-spark/
Matched naming pattern: python-ollama-spark
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 175
Registry downloads: 15/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2868 lines, 135.7 kB across 13 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ollama-spark' matches AI hallucination template [python] + [ollama] + [spark].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (173 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (2868 LOC across 13 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 356d 52 71 ↑0.1/day SUSPICIOUS deepseek pypi 0.1.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/langextract-deepseek/
Matched naming pattern: python-deepseek-langextract
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 52/month, 22/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 71 lines, 3.3 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'langextract-deepseek' matches AI hallucination template [python] + [deepseek] + [langextract].
  • HIGHClaims critical enterprise brand identity ('DEEPSEEK').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD