| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| md2x | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| mixer-tts-onnx | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| progressBarDistributed | 2026.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| claude-purr | 0.1.1 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| aind-watchdog-service | 0.1.8 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionSuspicious Page LinksMaintainer History |
| puku-markdown | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| se-codeowners | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| authaction-python-sdk | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| MASA-Safe-RL | 0.3.1 |
4.0
|
suspicious | 04 Jun 2026 | Code ObfuscationMaintainer History |
| apsw | 3.53.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| pinky-provider | 0.1.0.dev1 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| opentelemetry-instrumentation-httpx2 | 0.0.0 |
6.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| kubernetes-pydra | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| dbt-tree | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| diamond-dev | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| breslin | 0.1.0 |
6.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| business-name-generator | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| hermetic-alpha | 0.1.3 |
4.0
|
safe | 04 Jun 2026 | Maintainer History |
| agent-grammar | 0.1.3 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| Robomow-BLE | 1.0.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| amsdal_models | 0.8.4 |
4.0
|
safe | 04 Jun 2026 | Maintainer History |
| rag-llm-infra | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| cherry-docs | 0.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| agave | 1.5.5 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationCredential HarvestingMaintainer History |
| skill-scan-cli | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| byn | 0.0.1 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| ai-for-research | 1.0.3 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| sparsevlm | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| agents-remember-mcp | 2.3.3 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| alchemyql | 0.0.4 |
4.0
|
safe | 04 Jun 2026 | Code ObfuscationMaintainer History |
| loredocs-cli | 0.1.0a1 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| loreconvo-cli | 0.1.0a1 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| ChemicalDice | 1.0.5 |
4.0
|
safe | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| arkhe | 0.2.0 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| rustdl | 0.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| tms320c6x-disassembler | 1.0.0 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| ampio-mqtt | 0.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| aio-lib-sandbox | 0.1.0a7 |
4.0
|
safe | 04 Jun 2026 | Outbound Network CallsCode ObfuscationMaintainer History |
| CellProfiler-nightly | 5.0.0.dev643 |
3.0
|
safe | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| agledger | 0.8.15 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| aimu | 0.6.0 |
3.0
|
safe | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| arelle-release | 2.41.4 |
4.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| PyMkDB | 0.1.12 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| DipsScripting | 9.5.0 |
1.0
|
safe | 04 Jun 2026 | Maintainer History |
| ada-url | 1.32.0 |
4.0
|
safe | 04 Jun 2026 | Maintainer History |
| allspeak-ai | 260517181653 |
7.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| CryEx.v2 | 2.0.3 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| alogram-payrisk | 0.2.23 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-lsp | 0.13.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| ambara | 0.7.0 |
6.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |