| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| pychmp | 0.1.0 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| rosenbound | 0.1.1 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| aminx | 0.1.0a1 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| ardiq | 0.1.1 |
6.0
|
suspicious | 04 Jun 2026 | TyposquattingGit Repository HistoryMaintainer History |
| mcpindex-preflight | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| ascii-motion | 0.2.0 |
5.0
|
suspicious | 04 Jun 2026 | Suspicious Page LinksGit Repository HistoryMaintainer History |
| official-ip-fetcher-xethhung12 | 0.0.1 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| jirabatch | 0.10.0 |
4.0
|
safe | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| official-ip-fetcher | 0.0.1 |
4.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| recall-terminal | 0.1.2 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| hermes-workflow | 0.1.3 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| fiducial-targets | 0.0.1.dev1 |
5.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| openmlkitOCR | 1.0.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsMaintainer History |
| datasette-apps | 0.1a0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| cryoPARES | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionMaintainer History |
| md2x | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| mixer-tts-onnx | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| progressBarDistributed | 2026.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| claude-purr | 0.1.1 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| puku-markdown | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| se-codeowners | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| authaction-python-sdk | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| pinky-provider | 0.1.0.dev1 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| opentelemetry-instrumentation-httpx2 | 0.0.0 |
6.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| kubernetes-pydra | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| dbt-tree | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| diamond-dev | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| breslin | 0.1.0 |
6.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| business-name-generator | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| hermetic-alpha | 0.1.3 |
4.0
|
safe | 04 Jun 2026 | Maintainer History |
| Robomow-BLE | 1.0.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| rag-llm-infra | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| cherry-docs | 0.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| skill-scan-cli | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| byn | 0.0.1 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| sparsevlm | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| loredocs-cli | 0.1.0a1 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| loreconvo-cli | 0.1.0a1 |
4.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| rustdl | 0.2.0 |
6.0
|
suspicious | 04 Jun 2026 | Git Repository HistoryMaintainer History |
| tms320c6x-disassembler | 1.0.0 |
6.0
|
suspicious | 04 Jun 2026 | Code ObfuscationGit Repository HistoryMaintainer History |
| antihook | 0.1.2 |
5.0
|
suspicious | 04 Jun 2026 | Suspicious Page LinksMaintainer History |
| claudecast | 0.1.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| sast | 0.1.1 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| azure-ai-agentserver-ghcopilot | 0.0.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| loghunt | 0.1.0.dev0 |
7.0
|
suspicious | 04 Jun 2026 | Code ObfuscationCredential HarvestingMaintainer History |
| akashcli | 3.0.0 |
6.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| beeui | 0.13.0 |
6.0
|
suspicious | 04 Jun 2026 | Shell / Subprocess ExecutionCredential HarvestingSuspicious Page LinksMaintainer History |
| azure-storage-extensions | 0.0.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |
| geo-audit | 0.1.0 |
5.0
|
suspicious | 04 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| mubit-llama-index | 0.6.0 |
4.0
|
suspicious | 04 Jun 2026 | Maintainer History |