| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| agenizai-sdk | 2.4.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| warpos | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationCredential HarvestingMaintainer History |
| openstax-scraper | 0.1.3 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| quantum-lattice-models | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| engrami | 0.3.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationCredential HarvestingSuspicious Page Links+1 |
| operativa-mcp | 0.1.3 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| langchain-thalam | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-os-base | 0.2.9 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| agentseek | 0.0.2 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| wyattmcph-claude-monitor | 3.2.1 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| myrm-agent-harness-core-linux-x64 | 0.1.0rc1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| myrm-agent-harness-core-linux-arm64 | 0.1.0rc1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| myrm-agent-harness-core-darwin-x64 | 0.1.0rc1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| myrm-agent-harness-core-darwin-arm64 | 0.1.0rc1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| tun-camembert-ner | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agentcrew-ai | 0.16.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| simplyllm | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| snakemake-executor-plugin-panda | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| documind | 0.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| clanker-gguf | 1.0.4 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| bipixie-mcp | 0.3.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| raeh-data | 0.1.0 |
8.0
|
suspicious | 05 Jun 2026 | Credential HarvestingMaintainer History |
| rescue-lung-sdk | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| aa-market-manager | 2.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| seemseam-plan-tree | 0.2.1 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| cheminot | 1.0.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| malzapper-core | 2.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| myrm-agent-harness | 0.1.0rc1 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agentgrep | 0.1.0a17 |
3.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| diff-fret | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| diff-epr | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| diff-em | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| diff-hdx | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| langchain-talor-serp | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| nodus-workflow | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| bp3m | 2.0.0 |
5.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| airoles | 0.6.2 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| ltc-kl | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| agent-first-data | 0.12.1 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| bankofai-x402-gateway | 0.6.1b0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionSuspicious Page Links+2 |
| localbiz-page | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| xiaokeer.agent.harness | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| munk | 0.0.1 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| metabrain | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| nfctester | 0.0.37 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| WebBrokerAPI | 1.2606.502 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| lantern-sdk | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| mcp-registry-client | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| air-blackbox | 1.13.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+1 |
| hartrace | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |