Live

Threat Feed

Newly detected slopsquatted, typosquatted, and phantom packages across all major ecosystems.

8
Total Threats
2
Critical
4
High
4
Ecosystems Hit
By Ecosystem
npmPyPIRubyGemsGo01234
By Risk Level
  • critical
  • high
  • medium
By Threat Type
02468slopsquatphantom
npmcrypt0-utils
☠ CRITICALslopsquatvia community3 months ago

Active credential exfiltration package. Hallucinated by ChatGPT-4 and Claude. Steals .env files on postinstall. 847 confirmed infections.

PyPIpython-requests-async
☠ CRITICALslopsquatvia community3 months ago

Phantom async HTTP package. Consistently hallucinated by ChatGPT-4o. Exfiltrates AWS credentials. Responsible for confirmed $34k+ in fraudulent cloud charges.

RubyGemsruby-json-parser-fast
◆ MEDIUMslopsquatvia automated3 months ago

Claude 3 Haiku suggests this for fast JSON parsing. Logs all parsed JSON containing 'password' or 'token' keys to a remote endpoint.

npmexpress-security-utils
⚠ HIGHphantomvia admin3 months ago

New package registered this week. Zero legitimate use history. Name pattern matches AI hallucination signatures. Treat as hostile.

PyPIdjango-api-helper
◆ MEDIUMslopsquatvia community3 months ago

Hallucinated Django REST helper. Patches Django's authentication middleware to log credentials. Low sophistication but high spread via AI suggestions.

PyPIpandas-ml-utils
⚠ HIGHslopsquatvia community3 months ago

AI-hallucinated pandas ML extension. Delayed payload (30 days) makes attribution extremely difficult. Reverse shell to attacker infrastructure.

Gogo-http-client-utils
⚠ HIGHphantomvia automated3 months ago

Phantom Go HTTP library. Multiple AI models hallucinate this package name. Known exfiltration of Authorization headers from HTTP requests.

npmaxios-fetch-helper
⚠ HIGHslopsquatvia automated3 months ago

GitHub Copilot frequently suggests this non-existent package for combining axios and fetch. Contains keylogger activating after 100 keypresses.