Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
95 129d 133 26 ↑1.0/day SUSPICIOUS openai pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-ai-openai/
Matched naming pattern: atoti-openai-ai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 129
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 133/month, 28/week (MODERATE_USAGE)
Codebase size: 26 lines, 867 Bytes across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-ai-openai' matches AI hallucination template [atoti] + [openai] + [ai].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (128 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (128 days ago, 4 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 133 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 129d 141 136 ↑1.1/day SUSPICIOUS openai pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-ai-openai/
Matched naming pattern: atoti-openai-ai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 129
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 141/month, 32/week (MODERATE_USAGE)
Codebase size: 136 lines, 6.0 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-ai-openai' matches AI hallucination template [atoti] + [openai] + [ai].
  • HIGHClaims critical enterprise brand identity ('OPENAI').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (128 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (128 days ago, 4 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 141 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 168d 115 27 ↑0.7/day SUSPICIOUS gcp pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-storage-gcp/
Matched naming pattern: atoti-gcp-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 115/month, 14/week (MODERATE_USAGE)
Codebase size: 27 lines, 832 Bytes across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-storage-gcp' matches AI hallucination template [atoti] + [gcp] + [storage].
  • HIGHClaims critical enterprise brand identity ('GCP').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 115 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 168d 145 27 ↑0.9/day SUSPICIOUS azure pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-storage-azure/
Matched naming pattern: atoti-azure-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 145/month, 61/week (MODERATE_USAGE)
Codebase size: 27 lines, 836 Bytes across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-storage-azure' matches AI hallucination template [atoti] + [azure] + [storage].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 145 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 168d 167 26 ↑1.0/day SUSPICIOUS amazon pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-ai-amazon-bedrock/
Matched naming pattern: atoti-amazon-ai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 167/month, 22/week (MODERATE_USAGE)
Codebase size: 26 lines, 869 Bytes across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-ai-amazon-bedrock' matches AI hallucination template [atoti] + [amazon] + [ai].
  • HIGHClaims critical enterprise brand identity ('AMAZON').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 167 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 168d 160 41 ↑1.0/day SUSPICIOUS azure pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-storage-azure/
Matched naming pattern: django-azure-auth
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 160/month, 59/week (MODERATE_USAGE)
Codebase size: 41 lines, 2.0 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-storage-azure' matches AI hallucination template [django] + [azure] + [auth].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'ActiveViam <atoti-dev@activeviam.com>' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 160 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
95 168d 181 122 ↑1.1/day SUSPICIOUS amazon pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-ai-amazon-bedrock/
Matched naming pattern: atoti-amazon-ai
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 181/month, 24/week (MODERATE_USAGE)
Codebase size: 122 lines, 5.4 kB across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-ai-amazon-bedrock' matches AI hallucination template [atoti] + [amazon] + [ai].
  • HIGHClaims critical enterprise brand identity ('AMAZON').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 181 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
75 168d 114 19 ↑0.7/day SQUATTED_STUB gcp pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-storage-gcp/
Matched naming pattern: atoti-gcp-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Registry downloads: 114/month, 16/week (MODERATE_USAGE)
Codebase size: 19 lines, 715 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-storage-gcp' matches AI hallucination template [atoti] + [gcp] + [storage].
  • HIGHClaims critical enterprise brand identity ('GCP').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (19 LOC, 1 file(s), 715 bytes).
  • INFOModerate community usage with 114 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
65 753d 70 19 ↑0.1/day SQUATTED_STUB gcp pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-gcp/
Matched naming pattern: atoti-gcp-gcp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Registry downloads: 70/month, 32/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 19 lines, 705 Bytes across 2 files (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-gcp' matches AI hallucination template [atoti] + [gcp] + [gcp].
  • HIGHClaims critical enterprise brand identity ('GCP').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (19 LOC, 2 file(s), 705 bytes).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
65 753d 70 9 ↑0.1/day SQUATTED_STUB gcp pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-gcp/
Matched naming pattern: atoti-gcp-gcp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Registry downloads: 70/month, 33/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 9 lines, 352 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-gcp' matches AI hallucination template [atoti] + [gcp] + [gcp].
  • HIGHClaims critical enterprise brand identity ('GCP').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (9 LOC, 1 file(s), 352 bytes).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
55 753d 124 10 ↑0.2/day SQUATTED_STUB azure pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-azure/
Matched naming pattern: atoti-azure-azure
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Registry downloads: 124/month, 83/week (MODERATE_USAGE)
Codebase size: 10 lines, 428 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-azure' matches AI hallucination template [atoti] + [azure] + [azure].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (10 LOC, 1 file(s), 428 bytes).
  • INFOModerate community usage with 124 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
55 753d 150 19 ↑0.2/day SQUATTED_STUB azure pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-azure/
Matched naming pattern: atoti-azure-azure
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Registry downloads: 150/month, 92/week (MODERATE_USAGE)
Codebase size: 19 lines, 723 Bytes across 2 files (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-azure' matches AI hallucination template [atoti] + [azure] + [azure].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (19 LOC, 2 file(s), 723 bytes).
  • INFOModerate community usage with 150 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
17 168d 2,950 27 ↑17.6/day BENIGN_COMMUNITY aws pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-storage-aws/
Matched naming pattern: atoti-aws-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Registry downloads: 2950/month, 168/week (ACTIVE_COMMUNITY_USE)
Codebase size: 27 lines, 832 Bytes across 3 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-storage-aws' matches AI hallucination template [atoti] + [aws] + [storage].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'ActiveViam <atoti-dev@activeviam.com>' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 1 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOActive community usage with 2,950 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
17 168d 2,959 93 ↑17.6/day BENIGN_COMMUNITY aws pypi 6.2.0 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-storage-aws/
Matched naming pattern: atoti-aws-storage
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 168
Registry downloads: 2959/month, 173/week (ACTIVE_COMMUNITY_USE)
Codebase size: 93 lines, 3.9 kB across 6 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-storage-aws' matches AI hallucination template [atoti] + [aws] + [storage].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • HIGHPackage registered recently (167 days ago) during the active AI hallucination slopsquatting wave.
  • MEDIUMPackage registered with suspiciously high major version (v6.2.0, major 6) despite recent registration (167 days ago, 5 release(s)), indicating potential dependency confusion attack to shadow internal organization builds.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOActive community usage with 2,959 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
9 753d 3,089 19 ↑4.1/day BENIGN_COMMUNITY aws pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-server-aws/
Matched naming pattern: atoti-aws-aws
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Code-only verdict: SQUATTED_STUB (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 3089/month, 218/week (ACTIVE_COMMUNITY_USE)
Codebase size: 19 lines, 705 Bytes across 2 files (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-server-aws' matches AI hallucination template [atoti] + [aws] + [aws].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (19 LOC, 2 file(s), 705 bytes).
  • INFOActive community usage with 3,089 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
9 753d 3,074 14 ↑4.1/day BENIGN_COMMUNITY aws pypi 0.9.16 ActiveViam atoti-dev@activeviam.com activeviam.com
Claimed homepage: https://pypi.org/project/atoti-client-aws/
Matched naming pattern: atoti-aws-aws
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 753
Code-only verdict: SQUATTED_STUB (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 3074/month, 201/week (ACTIVE_COMMUNITY_USE)
Codebase size: 14 lines, 509 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • MEDIUMPackage name 'atoti-client-aws' matches AI hallucination template [atoti] + [aws] + [aws].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'atoti-dev@activeviam.com' is not affiliated with official vendor domain.
  • INFOEstablished pre-AI legacy package registered 752 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (14 LOC, 1 file(s), 509 bytes).
  • INFOActive community usage with 3,074 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD