Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
195 343d 9,504 12 ↑27.7/day MALICIOUS base pypi 54.3.1
Claimed homepage: https://pypi.org/project/gamspy-base/
Matched naming pattern: python-base-gamspy
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 343
Code-only verdict: SQUATTED_STUB (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 9504/month, 2766/week (ACTIVE_COMMUNITY_USE)
Codebase size: 12 lines, 5.2 kB across 2 files (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'gamspy-base' matches AI hallucination template [python] + [base] + [gamspy].
  • HIGHClaims critical enterprise brand identity ('BASE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 30 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 341 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v54.3.1, major 54) despite recent registration (341 days ago, 30 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 221d 19 92 ↑0.1/day MALICIOUS grok pypi 1768531.555.964 SuperMaker
Claimed homepage: https://supermaker.ai/blog/-grok-image-generator-model-on-supermaker-ai-twitterready-images-made-simple/
Matched naming pattern: grok-grok-generator
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 221
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 19/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 92 lines, 4.3 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'grok-image-generator' matches AI hallucination template [grok] + [grok] + [generator].
  • HIGHClaims critical enterprise brand identity ('GROK').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 220 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1768531.555.964, major 1768531) despite recent registration (220 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
185 223d 19 105 ↑0.1/day MALICIOUS grok pypi 1768377.239.270 SuperMaker
Claimed homepage: https://supermaker.ai/blog/grok-ai-video-generator-the-ultimate-guide-to-creating-ai-videos-2025/
Matched naming pattern: grok-grok-generator
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 223
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 19/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 105 lines, 4.4 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'grok-video-generator' matches AI hallucination template [grok] + [grok] + [generator].
  • HIGHClaims critical enterprise brand identity ('GROK').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 222 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1768377.239.270, major 1768377) despite recent registration (222 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
165 93d 13 1,034 ↑0.1/day MALICIOUS claude pypi 202605.0
Claimed homepage: https://pypi.org/project/powerline-claude-code/
Matched naming pattern: powerline-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 93
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1034 lines, 47.0 kB across 6 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'powerline-claude-code' matches AI hallucination template [powerline] + [claude] + [code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (92 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v202605.0, major 202605) despite recent registration (92 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (1034 LOC across 6 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
160 107d 5,119 55,583 ↑47.8/day MALICIOUS llama pypi 10605.0.0 vladlearns@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/llama-cpp-bin/
Matched naming pattern: llama-llama-bin
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 107
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 5119/month, 1261/week (ACTIVE_COMMUNITY_USE)
Codebase size: 55583 lines, 3.0 MB across 219 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'llama-cpp-bin' matches AI hallucination template [llama] + [llama] + [bin].
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'vladlearns@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 187 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (106 days ago) during the active AI hallucination slopsquatting wave.
  • CRITICALPackage registered with suspiciously high major version (v10605.0.0, major 10605) despite recent registration (106 days ago, 187 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (55583 LOC across 219 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
155 196d 18 1,634 ↑0.1/day MALICIOUS vllm pypi 20260210 Xingkai Yu
Claimed homepage: https://pypi.org/project/nano-vllm-fork/
Matched naming pattern: nano-vllm-fork
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 196
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 18/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1634 lines, 87.3 kB across 19 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'nano-vllm-fork' matches AI hallucination template [nano] + [vllm] + [fork].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 194 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v20260210, major 20260210) despite recent registration (194 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (1634 LOC across 19 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
120 202d 18 98 ↑0.1/day MALICIOUS supermaker pypi 1770199.903.60 SuperMaker
Claimed homepage: https://supermaker.ai/blog/unlock-perfect-poses-the-ultimate-guide-to-ai-pose-generators/
Matched naming pattern: supermaker-supermaker-pose
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 202
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 18/month, 7/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 98 lines, 4.7 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 200 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1770199.903.60, major 1770199) despite recent registration (200 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
120 215d 17 112 ↑0.1/day MALICIOUS pardon pypi 1769073.596.343 SuperMaker
Claimed homepage: https://supermaker.ai/video/blog/unlocking-the-magic-of-pardon-dance-the-viral-video-effect-taking-over-social-media/
Matched naming pattern: python-pardon-dance
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 215
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 112 lines, 5.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 214 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1769073.596.343, major 1769073) despite recent registration (214 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
120 242d 12 90 ↑0.0/day MALICIOUS supermaker pypi 1766750.238.33 SuperMaker
Claimed homepage: https://supermaker.ai/image/
Matched naming pattern: supermaker-supermaker-image
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 242
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 12/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 90 lines, 3.9 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 240 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1766750.238.33, major 1766750) despite recent registration (240 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
120 242d 13 26 ↑0.1/day MALICIOUS supermaker pypi 1766749.30.966 SuperMaker
Claimed homepage: https://supermaker.ai/image/
Matched naming pattern: supermaker-supermaker-image
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 242
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 26 lines, 940 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 240 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v1766749.30.966, major 1766749) despite recent registration (240 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
120 313d 8 19 ↑0.0/day MALICIOUS base pypi 66.0.3 Yandex security@yandex-team.ru yandex-team.ru
Claimed homepage: https://ya.ru
Matched naming pattern: yandex-base-clients
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 313
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 8/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19 lines, 765 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'yandex-infradev-clients-base' matches AI hallucination template [yandex] + [base] + [clients].
  • HIGHClaims critical enterprise brand identity ('BASE').
  • INFOPublisher email domain '@yandex-team.ru' matches package identifier token 'yandex-team', verifying identifiable third-party organization ownership.
  • MEDIUMPackage registered 312 days ago within the 1-year AI tool proliferation window.
  • CRITICALPackage registered with suspiciously high major version (v66.0.3, major 66) despite recent registration (312 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 71h 142 57 ↑47.3/day SUSPICIOUS stripe pypi 0.1.0 Aldane Hutchinson
Claimed homepage: https://pypi.org/project/flaxon-stripe/
Matched naming pattern: python-stripe-flaxon
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 142/month, 142/week (MODERATE_USAGE)
Codebase size: 57 lines, 2.7 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'flaxon-stripe' matches AI hallucination template [python] + [stripe] + [flaxon].
  • HIGHClaims critical enterprise brand identity ('STRIPE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (2 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 142 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 3d 289 193 ↑96.3/day SUSPICIOUS aws pypi 3.1.1 Your Name you@example.com example.com
Claimed homepage: https://pypi.org/project/vintasend-aws-s3-attachments/
Matched naming pattern: vintasend-aws-s3
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 3
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 289/month, 289/week (MODERATE_USAGE)
Codebase size: 193 lines, 8.8 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vintasend-aws-s3-attachments' matches AI hallucination template [vintasend] + [aws] + [s3].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'you@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 3 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (2 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 289 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 4d 126 33 ↑31.5/day SUSPICIOUS huggingface pypi 0.1.0 leonardofurnielis@outlook.com outlook.com
Claimed homepage: https://pypi.org/project/parakeet-index-embeddings-huggingface/
Matched naming pattern: parakeet-huggingface-embeddings
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 4
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 126/month, 126/week (MODERATE_USAGE)
Codebase size: 33 lines, 1.6 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'parakeet-index-embeddings-huggingface' matches AI hallucination template [parakeet] + [huggingface] + [embeddings].
  • HIGHClaims critical enterprise brand identity ('HUGGINGFACE').
  • HIGHPublisher email 'leonardofurnielis@outlook.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (2 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 126 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 5d 111 106 ↑22.2/day SUSPICIOUS google pypi 0.1.0 mijael.gara@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/skycast-google/
Matched naming pattern: python-google-skycast
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 5
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 111/month, 111/week (MODERATE_USAGE)
Codebase size: 106 lines, 5.6 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'skycast-google' matches AI hallucination template [python] + [google] + [skycast].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'mijael.gara@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (4 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 111 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 6d 147 84 ↑24.5/day SUSPICIOUS ollama pypi 0.1.0 Khader author@example.com example.com
Claimed homepage: https://github.com/khmeeran/-ollama-json-fixer-python
Matched naming pattern: ollama-ollama-fixer
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 6
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 147/month, 147/week (MODERATE_USAGE)
Codebase size: 84 lines, 3.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ollama-json-fixer' matches AI hallucination template [ollama] + [ollama] + [fixer].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'author@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (5 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 147 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 6d 111 171 ↑18.5/day SUSPICIOUS claude pypi 0.5.2 husanhe@email.com email.com
Claimed homepage: https://pypi.org/project/sanhe_claude_code_plugin_marketplace/
Matched naming pattern: sanhe-claude-code
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 6
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 111/month, 111/week (MODERATE_USAGE)
Codebase size: 171 lines, 6.4 kB across 6 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'sanhe-claude-code-plugin-marketplace' matches AI hallucination template [sanhe] + [claude] + [code].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'husanhe@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (5 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 111 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 7d 113 67 ↑16.1/day SUSPICIOUS vllm pypi 0.1.0 Exionos
Claimed homepage: https://pypi.org/project/exionos-vllm/
Matched naming pattern: python-vllm-exionos
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 7
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 113/month, 113/week (MODERATE_USAGE)
Codebase size: 67 lines, 3.7 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'exionos-vllm' matches AI hallucination template [python] + [vllm] + [exionos].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (5 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 113 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 11d 134 17 ↑12.2/day SUSPICIOUS base pypi 0.1.0 mooncore-inc
Claimed homepage: https://pypi.org/project/demon-cry-base/
Matched naming pattern: demon-base-base
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 11
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 134/month, 12/week (MODERATE_USAGE)
Codebase size: 17 lines, 600 Bytes across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'demon-cry-base' matches AI hallucination template [demon] + [base] + [base].
  • HIGHClaims critical enterprise brand identity ('BASE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (10 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 134 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 12d 133 23 ↑11.1/day SUSPICIOUS langchain pypi 0.6.1
Claimed homepage: https://pypi.org/project/memstrata-langchain-conversational/
Matched naming pattern: memstrata-langchain-conversational
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 12
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 133/month, 8/week (MODERATE_USAGE)
Codebase size: 23 lines, 1.0 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'memstrata-langchain-conversational' matches AI hallucination template [memstrata] + [langchain] + [conversational].
  • HIGHClaims critical enterprise brand identity ('LANGCHAIN').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (11 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 133 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 13d 122 192 ↑9.4/day SUSPICIOUS azure pypi 0.1.0 Datus
Claimed homepage: https://pypi.org/project/datus-azure-common/
Matched naming pattern: datus-azure-common
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 13
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 122/month, 6/week (MODERATE_USAGE)
Codebase size: 192 lines, 7.3 kB across 1 file (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'datus-azure-common' matches AI hallucination template [datus] + [azure] + [common].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (12 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 122 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 13d 129 196 ↑9.9/day SUSPICIOUS gcp pypi 0.1.0 Datus
Claimed homepage: https://pypi.org/project/datus-gcp-common/
Matched naming pattern: datus-gcp-common
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 13
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 129/month, 8/week (MODERATE_USAGE)
Codebase size: 196 lines, 7.5 kB across 1 file (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'datus-gcp-common' matches AI hallucination template [datus] + [gcp] + [common].
  • HIGHClaims critical enterprise brand identity ('GCP').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (12 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 129 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 14d 128 148 ↑9.1/day SUSPICIOUS claude pypi 0.1.0 workitharder+pypi@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/claude-code-slug/
Matched naming pattern: claude-claude-slug
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 14
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 128/month, 9/week (MODERATE_USAGE)
Codebase size: 148 lines, 6.5 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-code-slug' matches AI hallucination template [claude] + [claude] + [slug].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'workitharder+pypi@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (13 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 128 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 15d 233 60 ↑15.5/day SUSPICIOUS google pypi 0.0.2 wordstotech
Claimed homepage: https://pypi.org/project/google-ai-mode-scraper-api/
Matched naming pattern: google-google-mode
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 15
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 233/month, 18/week (MODERATE_USAGE)
Codebase size: 60 lines, 2.5 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'google-ai-mode-scraper-api' matches AI hallucination template [google] + [google] + [mode].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (14 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 233 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 16d 166 158 ↑10.4/day SUSPICIOUS ollama pypi 0.1.0 Randy Christehusz
Claimed homepage: https://pypi.org/project/ollama-doctor/
Matched naming pattern: python-ollama-doctor
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 16
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 166/month, 7/week (MODERATE_USAGE)
Codebase size: 158 lines, 6.2 kB across 10 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ollama-doctor' matches AI hallucination template [python] + [ollama] + [doctor].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (15 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 166 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 19d 248 37 ↑13.1/day SUSPICIOUS base pypi 1.0.13.1
Claimed homepage: https://pypi.org/project/yxd-skill-ty-base/
Matched naming pattern: yxd-base-ty
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 19
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 248/month, 87/week (MODERATE_USAGE)
Codebase size: 37 lines, 1.2 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'yxd-skill-ty-base' matches AI hallucination template [yxd] + [base] + [ty].
  • HIGHClaims critical enterprise brand identity ('BASE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • HIGHPackage registered recently (18 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 248 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 19d 246 76 ↑12.9/day SUSPICIOUS llama pypi 0.1.1 Ice Phi
Claimed homepage: https://pypi.org/project/llama-index-guardrails-icephi/
Matched naming pattern: llama-llama-guardrails
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 19
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 246/month, 16/week (MODERATE_USAGE)
Codebase size: 76 lines, 3.2 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'llama-index-guardrails-icephi' matches AI hallucination template [llama] + [llama] + [guardrails].
  • HIGHClaims critical enterprise brand identity ('LLAMA').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (18 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 246 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 20d 265 80 ↑13.2/day SUSPICIOUS openai pypi 5.2.0 vaquarkhan@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/mcp-test-harness-openai-agents/
Matched naming pattern: mcp-openai-harness
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 20
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 265/month, 127/week (MODERATE_USAGE)
Codebase size: 80 lines, 3.0 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-test-harness-openai-agents' matches AI hallucination template [mcp] + [openai] + [harness].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'vaquarkhan@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (18 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.2.0, major 5) despite recent registration (18 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 265 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 20d 370 42 ↑18.5/day SUSPICIOUS xai pypi 5.1.0 Vaquar Khan
Claimed homepage: https://pypi.org/project/mcp-bastion-xai/
Matched naming pattern: mcp-xai-xai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 20
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 370/month, 35/week (MODERATE_USAGE)
Codebase size: 42 lines, 1.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-bastion-xai' matches AI hallucination template [mcp] + [xai] + [xai].
  • HIGHClaims critical enterprise brand identity ('XAI').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (19 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.1.0, major 5) despite recent registration (19 days ago, 3 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 370 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 20d 368 41 ↑18.4/day SUSPICIOUS ollama pypi 5.1.0 Vaquar Khan
Claimed homepage: https://pypi.org/project/mcp-bastion-ollama/
Matched naming pattern: mcp-ollama-ollama
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 20
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 368/month, 133/week (MODERATE_USAGE)
Codebase size: 41 lines, 1.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-bastion-ollama' matches AI hallucination template [mcp] + [ollama] + [ollama].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (18 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.1.0, major 5) despite recent registration (18 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 375 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 20d 374 44 ↑18.7/day SUSPICIOUS openai pypi 5.1.0 Vaquar Khan
Claimed homepage: https://pypi.org/project/mcp-bastion-openai-agents/
Matched naming pattern: mcp-openai-openai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 20
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 374/month, 42/week (MODERATE_USAGE)
Codebase size: 44 lines, 2.2 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-bastion-openai-agents' matches AI hallucination template [mcp] + [openai] + [openai].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (19 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.1.0, major 5) despite recent registration (19 days ago, 3 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 374 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 20d 134 26 ↑6.7/day SUSPICIOUS langchain pypi 0.1.0 hello@trizenx.com trizenx.com
Claimed homepage: https://pypi.org/project/viparse-langchain/
Matched naming pattern: python-langchain-viparse
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 20
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 134/month, 7/week (MODERATE_USAGE)
Codebase size: 26 lines, 1.6 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'viparse-langchain' matches AI hallucination template [python] + [langchain] + [viparse].
  • HIGHClaims critical enterprise brand identity ('LANGCHAIN').
  • HIGHPublisher email 'hello@trizenx.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (19 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 131 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 21d 375 127 ↑17.9/day SUSPICIOUS openai pypi 0.1.0a4 Blazing Customs
Claimed homepage: https://pypi.org/project/ppx-openai/
Matched naming pattern: python-openai-ppx
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 21
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 375/month, 23/week (MODERATE_USAGE)
Codebase size: 127 lines, 5.1 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ppx-openai' matches AI hallucination template [python] + [openai] + [ppx].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 3 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 375 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 21d 263 59 ↑12.5/day SUSPICIOUS solana pypi 1.2.2026080407 Ludovit Scholtz
Claimed homepage: https://pypi.org/project/arc76-solana/
Matched naming pattern: python-solana-arc76
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 21
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 263/month, 18/week (MODERATE_USAGE)
Codebase size: 59 lines, 3.4 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'arc76-solana' matches AI hallucination template [python] + [solana] + [arc76].
  • HIGHClaims critical enterprise brand identity ('SOLANA').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 263 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 21d 0 58 ↑0.0/day SUSPICIOUS bitcoin pypi 1.2.2026080407 Ludovit Scholtz
Claimed homepage: https://pypi.org/project/arc76-bitcoin/
Matched naming pattern: python-bitcoin-arc76
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 21
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 58 lines, 3.7 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'arc76-bitcoin' matches AI hallucination template [python] + [bitcoin] + [arc76].
  • HIGHClaims critical enterprise brand identity ('BITCOIN').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 21d 248 40 ↑11.8/day SUSPICIOUS ethereum pypi 1.2.2026080407 Ludovit Scholtz
Claimed homepage: https://pypi.org/project/arc76-ethereum/
Matched naming pattern: python-ethereum-arc76
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 21
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 248/month, 18/week (MODERATE_USAGE)
Codebase size: 40 lines, 2.2 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'arc76-ethereum' matches AI hallucination template [python] + [ethereum] + [arc76].
  • HIGHClaims critical enterprise brand identity ('ETHEREUM').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (20 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 248 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 23d 499 80 ↑21.7/day SUSPICIOUS xai pypi 5.2.0 vaquarkhan@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/mcp-test-harness-xai/
Matched naming pattern: mcp-xai-harness
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 23
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 499/month, 126/week (MODERATE_USAGE)
Codebase size: 80 lines, 2.8 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-test-harness-xai' matches AI hallucination template [mcp] + [xai] + [harness].
  • HIGHClaims critical enterprise brand identity ('XAI').
  • HIGHPublisher email 'vaquarkhan@gmail.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (21 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.2.0, major 5) despite recent registration (21 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 502 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 23d 502 80 ↑21.8/day SUSPICIOUS ollama pypi 5.2.0 vaquarkhan@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/mcp-test-harness-ollama/
Matched naming pattern: mcp-ollama-harness
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 23
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 502/month, 35/week (MODERATE_USAGE)
Codebase size: 80 lines, 2.9 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcp-test-harness-ollama' matches AI hallucination template [mcp] + [ollama] + [harness].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'vaquarkhan@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 4 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (21 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v5.2.0, major 5) despite recent registration (21 days ago, 4 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 499 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 23d 151 193 ↑6.6/day SUSPICIOUS eth pypi 2.3.2 devWorld335
Claimed homepage: https://pypi.org/project/eth-key-abi/
Matched naming pattern: eth-eth-abi
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 23
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 151/month, 6/week (MODERATE_USAGE)
Codebase size: 193 lines, 6.8 kB across 4 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'eth-key-abi' matches AI hallucination template [eth] + [eth] + [abi].
  • HIGHClaims critical enterprise brand identity ('ETH').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (22 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 151 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 24d 134 79 ↑5.6/day SUSPICIOUS azure pypi 0.1.2a2 private@private.org private.org
Claimed homepage: https://pypi.org/project/ovos-tts-plugin-azure/
Matched naming pattern: ovos-azure-plugin
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 24
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 134/month, 9/week (MODERATE_USAGE)
Codebase size: 79 lines, 3.9 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ovos-tts-plugin-azure' matches AI hallucination template [ovos] + [azure] + [plugin].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'private@private.org' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (22 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 134 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 26d 137 30 ↑5.3/day SUSPICIOUS google pypi 0.0.0 sc
Claimed homepage: https://pypi.org/project/shopee-skynet-shopee-noc-google-mcp-server/
Matched naming pattern: shopee-google-shopee
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 26
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 137/month, 11/week (MODERATE_USAGE)
Codebase size: 30 lines, 1.1 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'shopee-skynet-shopee-noc-google-mcp-server' matches AI hallucination template [shopee] + [google] + [shopee].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (25 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 137 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 28d 0 188 ↑0.0/day SUSPICIOUS perplexity pypi 0.4.0 constantin@glez.de glez.de
Claimed homepage: https://pypi.org/project/llm-perplexity-agent/
Matched naming pattern: llm-perplexity-agent
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 28
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 188 lines, 10.3 kB across 1 file (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'llm-perplexity-agent' matches AI hallucination template [llm] + [perplexity] + [agent].
  • HIGHClaims critical enterprise brand identity ('PERPLEXITY').
  • HIGHPublisher email 'constantin@glez.de' is not affiliated with official vendor domain.
  • MEDIUMPackage published 3 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (27 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 28d 158 118 ↑5.6/day SUSPICIOUS cursor pypi 1.0.0 Garv Arora 66058398+gaminization@users.noreply.github.com users.noreply.github.com
Claimed homepage: https://github.com/gaminization/teleop-cursor
Matched naming pattern: python-cursor-teleop
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 28
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 158/month, 6/week (MODERATE_USAGE)
Codebase size: 118 lines, 5.4 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'teleop-cursor' matches AI hallucination template [python] + [cursor] + [teleop].
  • HIGHClaims critical enterprise brand identity ('CURSOR').
  • HIGHPublisher email '66058398+gaminization@users.noreply.github.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (27 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 158 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 29d 358 104 ↑12.3/day SUSPICIOUS google pypi 0.0.1 Circles info@circlez.ai circlez.ai
Claimed homepage: https://github.com/circles-zone/google-drive--storage-local-python-package
Matched naming pattern: google-google-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 29
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 358/month, 82/week (MODERATE_USAGE)
Codebase size: 104 lines, 5.0 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'google-drive-storage-local' matches AI hallucination template [google] + [google] + [storage].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'info@circlez.ai' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (27 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 358 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 29d 148 15 ↑5.1/day SUSPICIOUS langchain pypi 0.0.0 projectmanoj itsmanojthapa@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/langchain-apple-fm/
Matched naming pattern: langchain-langchain-fm
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 29
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 148/month, 4/week (MODERATE_USAGE)
Codebase size: 15 lines, 521 Bytes across 6 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'langchain-apple-fm' matches AI hallucination template [langchain] + [langchain] + [fm].
  • HIGHClaims critical enterprise brand identity ('LANGCHAIN').
  • HIGHPublisher email 'itsmanojthapa@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (28 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 148 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 29d 156 61 ↑5.4/day SUSPICIOUS vllm pypi 0.1.0 your.email@example.com example.com
Claimed homepage: https://pypi.org/project/vllm-cleaner/
Matched naming pattern: python-vllm-cleaner
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 29
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 156/month, 5/week (MODERATE_USAGE)
Codebase size: 61 lines, 2.8 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vllm-cleaner' matches AI hallucination template [python] + [vllm] + [cleaner].
  • HIGHClaims critical enterprise brand identity ('VLLM').
  • HIGHPublisher email 'your.email@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (28 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 156 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 31d 141 30 ↑4.5/day SUSPICIOUS langgraph pypi 0.0.0 sc
Claimed homepage: https://pypi.org/project/sea-autodev-langgraph-server-sdk/
Matched naming pattern: sea-langgraph-langgraph
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 31
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 141/month, 2/week (MODERATE_USAGE)
Codebase size: 30 lines, 1.1 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'sea-autodev-langgraph-server-sdk' matches AI hallucination template [sea] + [langgraph] + [langgraph].
  • HIGHClaims critical enterprise brand identity ('LANGGRAPH').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (30 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 141 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 31d 159 65 ↑5.1/day SUSPICIOUS openai pypi 0.1.0 Ramprasad Gaddam
Claimed homepage: https://pypi.org/project/vouch-openai/
Matched naming pattern: python-openai-vouch
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 31
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 159/month, 4/week (MODERATE_USAGE)
Codebase size: 65 lines, 2.7 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'vouch-openai' matches AI hallucination template [python] + [openai] + [vouch].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (30 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 159 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 34d 34 58 ↑1.0/day SUSPICIOUS aws pypi 0.1.0
Claimed homepage: https://pypi.org/project/aws-browser-client/
Matched naming pattern: aws-aws-client
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 34
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 34/month, 7/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 58 lines, 2.3 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-browser-client' matches AI hallucination template [aws] + [aws] + [client].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (33 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 36d 38 28 ↑1.1/day SUSPICIOUS google pypi 1.0.0 logiover
Claimed homepage: https://pypi.org/project/apify-google-flights-scraper/
Matched naming pattern: apify-google-flights
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 36
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 38/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 28 lines, 1.4 kB across 1 file (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'apify-google-flights-scraper' matches AI hallucination template [apify] + [google] + [flights].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'None' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (34 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD