| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| alibabacloud.mcp-proxy | 0.2.6 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| Sample-test-lib | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| FamacasePytest | 0.1.4 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| aiohomematic-test-support | 2026.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| agloom | 0.1.93 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| aa-corptools-dashboard | 0.0.2 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| FourCIPP | 1.113.0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| DynamicAdaptor | 0.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| aether-robotics | 3.4.3 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+2 |
| akosha | 0.8.2 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| alobj2shp | 0.2.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| anthropic-haystack | 5.10.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| ai-toolkit-cli | 1.1.2 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| GeneVue | 0.0.9 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| Functions-d | 1.34 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsRegistered Email DomainMaintainer History |
| aperta | 0.2.0a0 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| arabic-repair | 0.1.0 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| RacksDB | 0.7.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| antchain-twc | 1.13.23 |
4.0
|
suspicious | 04 Jun 2026 | Code ObfuscationSuspicious Page LinksMaintainer History |
| arabic-rt | 0.1.4 |
5.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| adrs | 1.2.1 |
6.0
|
suspicious | 04 Jun 2026 | TyposquattingMaintainer History |
| PAWpy | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| alkham | 0.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Credential HarvestingGit Repository HistoryMaintainer History |
| Crawl4AI | 0.8.9 |
7.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionSuspicious Page Links+1 |
| aa-beltradar | 0.0.8 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| aivg | 0.4.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| SkyalyticAI | 0.2.1 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| academic-agent-toolkit | 0.1.3 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| TinyCTA | 0.13.1 |
4.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| agh | 0.2.1 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionTyposquattingSuspicious Page Links+1 |
| aa-buybackprogram | 2.3.4 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| JarvisPLOT | 1.4.0 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationMaintainer History |
| agenthog | 0.3.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationMaintainer History |
| Telethon-MCUB | 1.43.17 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionCredential HarvestingMaintainer History |
| agentscope-runtime | 1.1.6.post2 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsSuspicious Page LinksMaintainer History |
| adaptive-reliability-layer | 0.3.1 |
5.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| aiand | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| SplashScreen-engine | 2.0.7 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| a2y-smartray | 0.8.9 |
4.0
|
suspicious | 04 Jun 2026 | Suspicious Page LinksMaintainer History |
| antfly-sdk | 0.0.2.dev2 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| Jarvis-HEP | 1.6.24 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| PEGGHy-Viewer | 1.1.6 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| agent6 | 0.0.5 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| antma | 0.2.0 |
5.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| anygarden | 0.9.1 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationMaintainer History |
| DrissionGet | 1.2.1 |
6.0
|
suspicious | 04 Jun 2026 | Registered Email DomainSuspicious Page LinksMaintainer History |
| ai-relay | 0.4.30 |
7.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| agent-signing | 0.2.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| aicd | 1.5.6 |
7.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCredential HarvestingTyposquattingMaintainer History |
| aisurface | 1.0.2 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionCredential HarvestingGit Repository History+1 |