Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.
Sorted by risk score. Filter with email:, domain:, keyword:, or
version: (comma = OR within a field, space = AND across fields), age:<6h /
age:>90d for how recently a package was published (combine both for a range, e.g.
age:>1h age:<6h), or a bare word for a package-name search.
Click a package to see the signals behind its score before opening its registry page.
| Package | Score ▼ | Age | Users | Lines | Growth | Verdict | Targeted | Ecosystem | Version | Author | Email domain | Signals |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 160 | 107d | 5,119 | 55,583 | ↑47.8/day | MALICIOUS | llama | pypi | 10605.0.0 | — vladlearns@gmail.com | gmail.com | ||
|
Claimed homepage: https://pypi.org/project/llama-cpp-bin/
Matched naming pattern: llama-llama-bin
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 107
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 5119/month, 1261/week (ACTIVE_COMMUNITY_USE)
Codebase size: 55583 lines, 3.0 MB across 219 files (LARGE_CODEBASE)
Automated signals flagged:
Signals reflect what our detector observed, not a confirmed determination of wrongdoing. View package on PyPI → |
||||||||||||