bp3m

v2.0.0 suspicious
5.0
Medium Risk

Bayesian Pipeline for Proper Motion measurements using HST and Gaia

🤖 AI Analysis

Final verdict: SUSPICIOUS

The package shows low risks in direct malicious activities but has a high metadata risk due to its recent creation and lack of maintenance history, raising concerns about potential supply-chain attacks.

  • High metadata risk
  • Recent repository and package creation
Per-check LLM notes
  • Network: No network calls detected, which is normal and expected.
  • Shell: Shell execution appears to be related to installing Jupyter kernels, which is common for packages that integrate with Jupyter notebooks.
  • Obfuscation: No obfuscation patterns detected, indicating low risk.
  • Credentials: No credential harvesting patterns detected, indicating low risk.
  • Metadata: High risk due to recent repository and package creation, single version release, and lack of maintainer history.

🔬 Heuristic Checks

Outbound Network Calls

No suspicious network call patterns found

Code Obfuscation

No obfuscation patterns detected

Shell / Subprocess Execution score 4.0

Found 2 shell execution pattern(s)

  • ready registered result = subprocess.run( [sys.executable, '-m', 'jupyter', 'kernelspec', 'li
  • vironment as a kernel subprocess.run( [sys.executable, '-m', 'ipykernel', 'install',
Credential Harvesting

No credential harvesting patterns detected

Typosquatting

No typosquatting candidates detected

Registered Email Domain

Email domain looks legitimate: gmail.com>

Suspicious Page Links

All external links appear legitimate

Git Repository History score 5.0

Git history flags: Repository created very recently: 0 day(s) ago (2026-06-04T19:55:12Z)

  • Repository created very recently: 0 day(s) ago (2026-06-04T19:55:12Z)
  • All 54 commits happened within 24 hours
Maintainer History score 8.0

4 maintainer concern(s) found

  • Only one version has ever been released — brand new package
  • Package uploaded less than 24 hours ago (2026-06-05T02:34:15.000Z)
  • Author name is missing or very short
  • Author "" appears to have only 1 package on PyPI (new or inactive account)