AI Analysis
Final verdict: SUSPICIOUS
The package exhibits low risks in terms of network, shell, obfuscation, and credential misuse but has a high metadata risk due to recent rapid activity and lack of maintainer history.
- High metadata risk
- Lack of maintainer history
Per-check LLM notes
- Network: The package makes network calls to external services which seems reasonable for domain mapping and data retrieval purposes.
- Shell: No shell execution patterns were detected in the provided code snippets.
- Obfuscation: No obfuscation patterns detected, indicating low risk.
- Credentials: No credential harvesting patterns detected, indicating low risk.
- Metadata: The recent and rapid activity, coupled with the lack of maintainer history and repository engagement, raises concerns about potential malicious intent.
Heuristic Checks
Outbound Network Calls
score 9.0
Found 6 network call pattern(s)
allback).""" try: socket.setdefaulttimeout(DNS_TIMEOUT) socket.getaddrinfo(domain, None)try: resp = requests.get(url, params=params, headers=HEADERS, timeout=15)try: resp = requests.get( "https://www.sec.gov/files/company_tickers.try: resp = requests.get(url, headers=HEADERS, timeout=15) resp.raise_forndex.json" resp = requests.get(index_url, headers=HEADERS, timeout=15) resp.rairectly resp = requests.get(html_url, headers=HEADERS, timeout=15) resp.
Code Obfuscation
No obfuscation patterns detected
Shell / Subprocess Execution
No shell execution patterns detected
Credential Harvesting
No credential harvesting patterns detected
Typosquatting
No typosquatting candidates detected
Registered Email Domain
Email domain looks legitimate: gtmlayer.com>
Suspicious Page Links
All external links appear legitimate
Git Repository History
score 5.0
Git history flags: Repository has zero stars and zero forks
Repository has zero stars and zero forksAll 8 commits happened within 24 hours
Maintainer History
score 8.0
4 maintainer concern(s) found
Only one version has ever been released — brand new packagePackage uploaded less than 24 hours ago (2026-06-05T00:17:45.000Z)Author name is missing or very shortAuthor "" appears to have only 1 package on PyPI (new or inactive account)