Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
95 356d 13 17 ↑0.0/day SUSPICIOUS chroma pypi 3.343.40.2160 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-chroma/
Matched naming pattern: python-chroma-mcpbind
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 415 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-chroma' matches AI hallucination template [python] + [chroma] + [mcpbind].
  • HIGHClaims critical enterprise brand identity ('CHROMA').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage has empty or near-zero description (potential reservation stub).
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 17 17 ↑0.0/day SUSPICIOUS openai pypi 3.584.43.3842 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-openai-websearch-mcp/
Matched naming pattern: mcpbind-openai-websearch
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 471 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-openai-websearch-mcp' matches AI hallucination template [mcpbind] + [openai] + [websearch].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 13 17 ↑0.0/day SUSPICIOUS google pypi 3.577.30.9953 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-google-analytics-mcp/
Matched naming pattern: mcpbind-google-analytics
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 471 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-google-analytics-mcp' matches AI hallucination template [mcpbind] + [google] + [analytics].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 354 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 19 17 ↑0.1/day SUSPICIOUS stripe pypi 3.573.44.3084 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-stripe-agent-toolkit/
Matched naming pattern: mcpbind-stripe-agent
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 19/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 471 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-stripe-agent-toolkit' matches AI hallucination template [mcpbind] + [stripe] + [agent].
  • HIGHClaims critical enterprise brand identity ('STRIPE').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 354 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 15 17 ↑0.0/day SUSPICIOUS microsoft pypi 3.458.56.9547 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-microsoft-fabric-rti-mcp/
Matched naming pattern: mcpbind-microsoft-fabric
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 15/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 487 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-microsoft-fabric-rti-mcp' matches AI hallucination template [mcpbind] + [microsoft] + [fabric].
  • HIGHClaims critical enterprise brand identity ('MICROSOFT').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 13 17 ↑0.0/day SUSPICIOUS binance pypi 3.451.45.1959 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-binance-mcp-server/
Matched naming pattern: mcpbind-binance-mcp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 13/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 463 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-binance-mcp-server' matches AI hallucination template [mcpbind] + [binance] + [mcp].
  • HIGHClaims critical enterprise brand identity ('BINANCE').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 17 17 ↑0.0/day SUSPICIOUS workspace pypi 3.378.19.9413 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-workspace-mcp/
Matched naming pattern: mcpbind-workspace-mcp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 443 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-workspace-mcp' matches AI hallucination template [mcpbind] + [workspace] + [mcp].
  • HIGHClaims critical enterprise brand identity ('WORKSPACE').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 17 17 ↑0.0/day SUSPICIOUS chroma pypi 3.330.43.4976 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-chroma-mcp/
Matched naming pattern: mcpbind-chroma-mcp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 17/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 431 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-chroma-mcp' matches AI hallucination template [mcpbind] + [chroma] + [mcp].
  • HIGHClaims critical enterprise brand identity ('CHROMA').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
80 356d 0 17 ↑0.0/day SUSPICIOUS google pypi 3.241.33.7653 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-mcp-google-email/
Matched naming pattern: mcpbind-google-google
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 0/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 455 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'mcpbind-mcp-google-email' matches AI hallucination template [mcpbind] + [google] + [google].
  • HIGHClaims critical enterprise brand identity ('GOOGLE').
  • HIGHPublisher email 'mcpbind@example.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
5 356d 10 17 ↑0.0/day BENIGN_COMMUNITY mcpbind pypi 3.481.15.8566 mcpbind@example.com example.com
Claimed homepage: https://pypi.org/project/mcpbind-TigerGraph-MCP/
Matched naming pattern: django-mcpbind-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Registry downloads: 10/month, 0/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 17 lines, 447 Bytes across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage registered 354 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD