| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| WebBrokerAPI | 1.2606.502 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| lantern-sdk | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| mcp-registry-client | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| air-blackbox | 1.13.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+1 |
| hartrace | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationGit Repository HistoryMaintainer History |
| nemo-cli | 0.0.1 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| n0brains-cli | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| outfitter-dispatch | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| antchain-testhkfinal | 1.0.21 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationSuspicious Page LinksMaintainer History |
| deepcloak | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| loongsuite-instrumentation-wildtool | 0.6.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| dlz-logger | 0.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| aicu-scanner | 0.8.1 |
8.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+2 |
| loongsuite-instrumentation-widesearch | 0.6.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| TALLSorts | 0.3 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| etap-clf | 0.1.1 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| mudra-ml | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agentfoundry | 1.5.60 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| skillforge-agent | 1.0.1 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| byted-sophon-cli | 0.0.1 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| bytedance-autocli | 0.0.1 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| byted-seed-android-tasks-badcase-2606 | 0.0.1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| byted-modscript | 0.0.1 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| arkhe-db | 0.4.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| arkhe-core | 0.4.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| arkhe-config | 0.4.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| sadp-harness | 1.91 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| sandbox-cloud-harbor-environment | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| SpiffWorkflow | 3.1.2 |
4.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| sandbox-cloud-client | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| superwatt | 0.1.2 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| retrieval-observatory | 0.1.2 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| Rhapso | 0.3.2 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| agenix-manager | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| torchtitan-neuron | 0.0.1 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| nice-agent | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| extractx | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| therock-tools | 0.1.0 |
7.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionCredential Harvesting+1 |
| concordia-sdk-python | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| felits | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| adsorption | 0.0.6 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| sellsyde-mcp | 1.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| HeronIntelligence-mcp | 1.4.5 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| netdiag-cli | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| triangle-api | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| classmap-hanthink | 0.2.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| agent-executor | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| scm-python | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| jesco-tools | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| thonny-html-highlight | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |