| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| devfabeco-buildcore | 0.3.0 |
6.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionCredential HarvestingGit Repository HistoryMaintainer History |
| devfabeco-graph | 0.4.0 |
6.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| devfabeco-envcapsule | 0.3.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| devfabeco-library | 0.3.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| DataComparerLibrary | 0.860 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| zed-context-manipulator | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| ikkToolKit | 0.0.0 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| my-package-tanakit | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-fuel-sdk | 0.3.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| jupyterlab-acp | 0.0.1 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| qsim-uma | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| tgoti | 0.0.1 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| allianceauth-oidc-provider-eveo7 | 0.3.2 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsSuspicious Page LinksGit Repository HistoryMaintainer History |
| weatherbox-tanakit | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| gutshape | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionCredential HarvestingMaintainer History |
| win11-release-guard | 0.3.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| beautiful-brains | 0.0.1 |
8.0
|
suspicious | 05 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| sb-salt | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| codei-cli | 0.0.2 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| tracedsa | 1.0.0 |
6.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| kotti2-iframe | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| allocation | 0.0.1 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| visionbot-sdk | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| suede-ai | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationMaintainer History |
| envguard-bin | 1.0.3 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| specgate-cli | 0.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| claude-compress | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| nvexit | 1.0.1 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| stock-gateway | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| coactra | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| llamella | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| parosol-py | 0.1.3 |
5.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| pyagent-trace | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| pyagent-compress | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| pyagent-router | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| pyagent-patterns | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| agent-moss | 0.4.0 |
7.0
|
suspicious | 05 Jun 2026 | Code ObfuscationCredential HarvestingSuspicious Page LinksMaintainer History |
| mne-mcp | 0.2.0 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| OpenRCT2-ObjectCommon | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| aperture-engine | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| lmms-video-utils | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| 2sio | 0.24.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationTyposquattingGit Repository History+1 |
| agenizai-sdk | 2.4.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| warpos | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationCredential HarvestingMaintainer History |
| openstax-scraper | 0.1.3 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| quantum-lattice-models | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| engrami | 0.3.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationCredential HarvestingSuspicious Page Links+1 |
| operativa-mcp | 0.1.3 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| langchain-thalam | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-os-base | 0.2.9 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |