| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| ai302 | 1.0.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| pydalec | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| taiwan-payroll | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| PyGeoFetch | 0.1.4 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationCredential HarvestingGit Repository History+1 |
| ripple-impact-mcp | 1.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| nyra | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| clitag | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| goldenmatch-embed | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| AOT-biomaps | 2.9.731 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| cydeai-client | 0.1.1 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| braintoken-downloader | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| auto-rotate | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| pharnoss | 0.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| BharatFinTrack | 0.3.1 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| ag2 | 0.13.3 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionTyposquatting+1 |
| agent-os-server | 0.5.10 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksMaintainer History |
| hydros-agent-sdk | 0.1.4 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| eigh-cuda120 | 0.3.12 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| act-tester | 0.4.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| hydros-agent-sdk-preview-curryzxh | 0.1.4.dev1 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| dgsolve | 0.1.0a0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| pytest-api-contract | 0.3.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| test-report-dashboard | 0.3.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| fhi-decaf | 1.0.6 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksMaintainer History |
| pyrtipc | 0.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| rein-openhands | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| PeakPo | 7.10.12 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| agentflow-runtime | 1.5.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| loom-engine-rpg | 2.3.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| coding-agent-roi | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksGit Repository HistoryMaintainer History |
| test-witty | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionSuspicious Page LinksGit Repository HistoryMaintainer History |
| khadee-eda | 1.0.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| autoplay-setup | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| actaclad-agentguard | 1.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| apex-dispatch-api-client | 0.7.2 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| agentx-security-sdk | 0.2.11 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| FunKitPy | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| sccircuits | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| preship | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| aias-common | 1.15.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| huscy.data-acquisition-methods.questionnaire | 0.2.0a4 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| fitolit | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| skillrl | 1.0.0 |
7.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| l0l2learn | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| dataroma-mcp | 0.1.2 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| torch-proj-r06 | 1.0.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| tls-client-python | 1.14.0 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| Aerosol3D | 0.9.0 |
4.0
|
suspicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| pinky-tools | 0.1.0.dev1 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agentic-mcp-gateway | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionSuspicious Page LinksMaintainer History |