Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
95 258d 15 146 ↑0.1/day SUSPICIOUS aws pypi 1.0.4 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_tgw_routes
Matched naming pattern: aws-aws-routes
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 258
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 15/month, 4/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 146 lines, 5.2 kB across 4 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-tgw-routes' matches AI hallucination template [aws] + [aws] + [routes].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 4 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 256 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
16 222d 23 409 ↑0.1/day BENIGN_COMMUNITY aws pypi 1.2.0 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://pypi.org/project/get_aws_details/
Matched naming pattern: get-aws-details
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 222
Registry downloads: 23/month, 2/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 409 lines, 13.6 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'get-aws-details' matches AI hallucination template [get] + [aws] + [details].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage registered 221 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
14 533d 149 374 ↑0.3/day BENIGN_COMMUNITY aws pypi 1.1.0 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_secrets_vault
Matched naming pattern: aws-aws-vault
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 533
Registry downloads: 149/month, 68/week (MODERATE_USAGE)
Codebase size: 374 lines, 13.0 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-secrets-vault' matches AI hallucination template [aws] + [aws] + [vault].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 6 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOModerate community usage with 149 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
13 459d 28 681 ↑0.1/day BENIGN_COMMUNITY aws pypi 1.0.18 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_tgw_details
Matched naming pattern: aws-aws-details
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 459
Registry downloads: 28/month, 8/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 681 lines, 23.8 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-tgw-details' matches AI hallucination template [aws] + [aws] + [details].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 19 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (681 LOC across 2 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
13 945d 25 258 ↑0.0/day BENIGN_COMMUNITY aws pypi 1.2.8 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_crawler
Matched naming pattern: python-aws-crawler
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 945
Registry downloads: 25/month, 6/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 258 lines, 8.2 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-crawler' matches AI hallucination template [python] + [aws] + [crawler].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 18 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFOEstablished pre-AI legacy package registered 943 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
12 533d 1,124 234 ↑2.1/day BENIGN_COMMUNITY aws pypi 2.0.8 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_authenticator
Matched naming pattern: python-aws-authenticator
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 533
Registry downloads: 1124/month, 237/week (ACTIVE_COMMUNITY_USE)
Codebase size: 234 lines, 8.3 kB across 2 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-authenticator' matches AI hallucination template [python] + [aws] + [authenticator].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 9 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOActive community usage with 1,124 monthly downloads.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
10 661d 21 1,346 ↑0.0/day BENIGN_COMMUNITY aws pypi 2.4.4 Ahmad Ferdaus Abd Razak fer1035@gmail.com gmail.com
Claimed homepage: https://gitlab.com/fer1035_python/modules/pypi-aws_administrator
Matched naming pattern: python-aws-administrator
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 661
Registry downloads: 21/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 1346 lines, 51.9 kB across 19 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'aws-administrator' matches AI hallucination template [python] + [aws] + [administrator].
  • HIGHClaims critical enterprise brand identity ('AWS').
  • HIGHPublisher email 'fer1035@gmail.com' is not affiliated with official vendor domain.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (1346 LOC across 19 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD