| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| CiliaTracks | 1.1.6 |
3.0
|
suspicious | 03 Jun 2026 | Code ObfuscationMaintainer History |
| archinfo | 9.2.221 |
4.0
|
suspicious | 03 Jun 2026 | Code ObfuscationMaintainer History |
| angr-management | 9.2.221 |
4.0
|
suspicious | 03 Jun 2026 | Maintainer History |
| abstract-queries | 0.0.0.115 |
3.0
|
suspicious | 03 Jun 2026 | Git Repository HistoryMaintainer History |
| abstract-security | 0.81 |
4.0
|
suspicious | 03 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| abstract-database | 0.0.2.185 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| amplitude-ai | 1.8.0 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationMaintainer History |
| aiidalab-widgets-base | 2.5.1 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+2 |
| alvz-lenguaje | 0.18.0 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| MEGnet-neuro | 0.3.3 |
5.0
|
suspicious | 03 Jun 2026 | Code ObfuscationMaintainer History |
| arize-phoenix | 17.2.0 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+2 |
| aplicacion-ventas-ctipan | 0.1.1 |
4.0
|
suspicious | 03 Jun 2026 | Git Repository HistoryMaintainer History |
| anch-hash | 1.0.0 |
4.0
|
suspicious | 03 Jun 2026 | Git Repository HistoryMaintainer History |
| Dev10x | 0.78.0 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| abicheck | 0.3.0 |
5.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| aranda-skills | 0.1.0 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsMaintainer History |
| acemd | 4.1.3 |
7.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| apc-model-parser | 0.2.2 |
4.0
|
suspicious | 03 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-borg | 3.3.18 |
6.0
|
suspicious | 03 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionCredential HarvestingGit Repository History+1 |
| aarg-canvas | 0.1.0 |
5.0
|
suspicious | 03 Jun 2026 | Registered Email DomainMaintainer History |
| aorta-sirius | 0.131 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| aorta-sirius-dev | 0.275 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| agentis-verify | 0.1.0 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsMaintainer History |
| alpacloud.crdvis | 0.1.1 |
5.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionSuspicious Page LinksMaintainer History |
| aiohomematic-contract | 2026.6.1 |
4.0
|
suspicious | 03 Jun 2026 | Git Repository HistoryMaintainer History |
| alloy-runtime-cli | 0.2.107 |
5.0
|
suspicious | 03 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| alloy-runtime-sdk | 0.2.107 |
6.0
|
suspicious | 03 Jun 2026 | Code ObfuscationMaintainer History |
| agentadmit | 1.0.0 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsMaintainer History |
| airos | 0.6.8 |
4.0
|
suspicious | 03 Jun 2026 | TyposquattingMaintainer History |
| KangelPluginsManager | 1.4.1.1 |
3.0
|
suspicious | 03 Jun 2026 | Maintainer History |
| agent-devex | 0.29.1 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| agex-cli | 0.29.1 |
5.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| NLPPlus | 2.0.4 |
6.0
|
suspicious | 03 Jun 2026 | Suspicious Page LinksMaintainer History |
| archextractor | 0.2.0 |
4.0
|
suspicious | 03 Jun 2026 | Maintainer History |
| apache-airflow-ctl | 0.1.5 |
6.0
|
suspicious | 03 Jun 2026 | Code ObfuscationCredential HarvestingSuspicious Page LinksMaintainer History |
| amd-gaia | 0.20.0 |
8.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+1 |
| agentvault-hermes | 0.7.8 |
5.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| agentlane | 0.9.0 |
4.0
|
suspicious | 03 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| aigie | 0.2.43 |
6.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| agent-failsafe | 0.6.1 |
5.0
|
suspicious | 03 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| actionguard | 0.2.1 |
6.0
|
suspicious | 03 Jun 2026 | Credential HarvestingGit Repository HistoryMaintainer History |
| CK-InoDrive-API | 1.0.2 |
5.0
|
suspicious | 03 Jun 2026 | Code ObfuscationMaintainer History |
| agentguard-security | 0.1.0 |
7.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionCredential HarvestingGit Repository History+1 |
| ai-salom-x391 | 2.1.1 |
4.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| alpha-id-zix | 0.3.1 |
7.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsCode ObfuscationCredential HarvestingGit Repository History+1 |
| alarm-clock-cli | 0.1.1 |
5.0
|
suspicious | 03 Jun 2026 | Maintainer History |
| a2al | 0.2.7 |
5.0
|
suspicious | 03 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| alibabacloud-wuyingai20260311 | 1.1.1 |
4.0
|
suspicious | 03 Jun 2026 | Code ObfuscationSuspicious Page LinksMaintainer History |
| adb-wifi-qr | 0.2.0 |
5.0
|
suspicious | 03 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| agent-conveyor | 0.1.0 |
5.0
|
suspicious | 03 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |