Automated package-squatting & slopsquatting detection signals across PyPI and npm — these are automated, unconfirmed signals. Use them to find candidates to investigate, but don't automatically assume they're malicious.

Sorted by risk score. Filter with email:, domain:, keyword:, or version: (comma = OR within a field, space = AND across fields), age:<6h / age:>90d for how recently a package was published (combine both for a range, e.g. age:>1h age:<6h), or a bare word for a package-name search. Click a package to see the signals behind its score before opening its registry page.

Package Score Age Users Lines Growth Verdict Targeted Ecosystem Version Author Email domain Signals
95 356d 52 71 ↑0.1/day SUSPICIOUS deepseek pypi 0.1.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/langextract-deepseek/
Matched naming pattern: python-deepseek-langextract
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 356
Code-only verdict: BENIGN_COMMUNITY (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 52/month, 22/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 71 lines, 3.3 kB across 2 files (TINY_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'langextract-deepseek' matches AI hallucination template [python] + [deepseek] + [langextract].
  • HIGHClaims critical enterprise brand identity ('DEEPSEEK').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 355 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
18 156d 28 2,711 ↑0.2/day BENIGN_COMMUNITY gemini pypi 2.4.12 Your Name your@email.com email.com
Claimed homepage: https://github.com/dsdanielpark/Gemini-API
Matched naming pattern: gemini-gemini-api
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 156
Registry downloads: 28/month, 18/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2711 lines, 114.7 kB across 31 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'gemini-firefox-api' matches AI hallucination template [gemini] + [gemini] + [api].
  • HIGHClaims critical enterprise brand identity ('GEMINI').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (155 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (2711 LOC across 31 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
18 175d 15 2,868 ↑0.1/day BENIGN_COMMUNITY ollama pypi 0.1.1 your@email.com email.com
Claimed homepage: https://pypi.org/project/ollama-spark/
Matched naming pattern: python-ollama-spark
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 175
Registry downloads: 15/month, 3/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 2868 lines, 135.7 kB across 13 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'ollama-spark' matches AI hallucination template [python] + [ollama] + [spark].
  • HIGHClaims critical enterprise brand identity ('OLLAMA').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • HIGHPackage registered recently (173 days ago) during the active AI hallucination slopsquatting wave.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (2868 LOC across 13 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
16 190d 23 980 ↑0.1/day BENIGN_COMMUNITY claude pypi 0.1.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/claude-to-whatsapp/
Matched naming pattern: claude-claude-whatsapp
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 190
Registry downloads: 23/month, 9/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 980 lines, 45.1 kB across 22 files (MODERATE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'claude-to-whatsapp' matches AI hallucination template [claude] + [claude] + [whatsapp].
  • HIGHClaims critical enterprise brand identity ('CLAUDE').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 1 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 189 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (980 LOC across 22 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
16 245d 12 4,674 ↑0.0/day BENIGN_COMMUNITY azure pypi 1.17.0a1 your@email.com email.com
Claimed homepage: https://pypi.org/project/azure-functions-test/
Matched naming pattern: azure-azure-test
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 245
Registry downloads: 12/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 4674 lines, 233.3 kB across 31 files (LARGE_CODEBASE)
Automated signals flagged:
  • MEDIUMPackage name 'azure-functions-test' matches AI hallucination template [azure] + [azure] + [test].
  • HIGHClaims critical enterprise brand identity ('AZURE').
  • HIGHPublisher email 'your@email.com' is not affiliated with official vendor domain.
  • MEDIUMPackage published 2 versions in rapid succession (< 24h) to mimic mature open source maintenance.
  • MEDIUMPackage registered 244 days ago within the 1-year AI tool proliferation window.
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (4674 LOC across 31 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
5 398d 11 3,004 ↑0.0/day BENIGN_COMMUNITY shopify pypi 0.2.0 your@email.com email.com
Claimed homepage: https://pypi.org/project/shopify-client-oliver/
Matched naming pattern: shopify-shopify-oliver
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 398
Registry downloads: 11/month, 5/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 3004 lines, 100.7 kB across 29 files (LARGE_CODEBASE)
Automated signals flagged:
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • INFOSubstantial functional codebase (3004 LOC across 29 file(s)).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →
5 857d 11 13 ↑0.0/day BENIGN_COMMUNITY discord pypi 1 mao your@email.com email.com
Claimed homepage: https://github.com/yourusername/discord-control
Matched naming pattern: python-discord-controler
Official vendor account: No — publisher domain doesn't match the brand it names
Days since publish: 857
Code-only verdict: SQUATTED_STUB (the score above also weighs naming and publisher-domain signals, not just the code itself)
Registry downloads: 11/month, 1/week (NEGLIGIBLE_OR_ZERO_USAGE)
Codebase size: 13 lines, 380 Bytes across 1 file (EMPTY_STUB)
Automated signals flagged:
  • INFOEstablished pre-AI legacy package registered 856 days ago (predates modern AI hallucination waves).
  • INFONo malicious install-time hooks or shell cradles detected in package AST.
  • MEDIUMPackage is an empty placeholder (13 LOC, 1 file(s), 380 bytes).

Signals reflect what our detector observed, not a confirmed determination of wrongdoing.

View package on PyPI →

LINK COPIED TO CLIPBOARD