CRYPTO-UTILS NOT FOUND |FLASK-HELPERS NOT FOUND |DATA-FRAME-UTILS 12 DAYS OLD |PIP-UTILS 43 DOWNLOADS |AI-UTILS NOT FOUND |ML-HELPERS NOT FOUND |NODE-FETCH2 87 DOWNLOADS |TORCH-UTILS NOT FOUND |CRYPTO-UTILS NOT FOUND |FLASK-HELPERS NOT FOUND |DATA-FRAME-UTILS 12 DAYS OLD |PIP-UTILS 43 DOWNLOADS |AI-UTILS NOT FOUND |ML-HELPERS NOT FOUND |NODE-FETCH2 87 DOWNLOADS |TORCH-UTILS NOT FOUND |CRYPTO-UTILS NOT FOUND |FLASK-HELPERS NOT FOUND |DATA-FRAME-UTILS 12 DAYS OLD |PIP-UTILS 43 DOWNLOADS |AI-UTILS NOT FOUND |ML-HELPERS NOT FOUND |NODE-FETCH2 87 DOWNLOADS |TORCH-UTILS NOT FOUND |CRYPTO-UTILS NOT FOUND |FLASK-HELPERS NOT FOUND |DATA-FRAME-UTILS 12 DAYS OLD |PIP-UTILS 43 DOWNLOADS |AI-UTILS NOT FOUND |ML-HELPERS NOT FOUND |NODE-FETCH2 87 DOWNLOADS |TORCH-UTILS NOT FOUND
THREAT INTEL
· fetching...LIVESCAN YOUR MANIFEST
PASTE. SCAN.
FIND OUT.
[01] PROBLEM
THE SLOPSQUATTING
THREAT
Slopsquatting is a documented, active threat. AI models suggest package names that don't exist - threat actors register those names on public registries within hours, load them with malicious install scripts, and wait. Hook Check cross-checks every dependency in your manifest against live registry data, download history, and the OSV vulnerability database before a single byte executes.
--
--
--
[02] WHAT WE CHECK
FIVE FLAGS.
ZERO ACCOUNTS.
❌NONEXISTENTPackage returns 404 on registrye.g. crypto-utils
⚠️NEWLY REGISTEREDCreated less than 30 days agoe.g. ml-utils-py
⚠️LOW DOWNLOADSBelow ecosystem download floornpm <500/mo |PyPI <200/mo
⚠️POST-INSTALL SCRIPTScript calls curl, wget, or evale.g. postinstall: curl | sh
✅LEGITExists, old enough, trusted volumee.g. numpy, flask, express
[03] HOW IT WORKS
THREE STEPS.
TWO SECONDS.
01 /
PASTE
Drop your package.json or
requirements.txt into the box.
02 /
SCAN
We hit npm + PyPI directly
from your browser.
No server. No logs.
03 /
REVIEW
Results ranked by severity.
Export or fix.
[04] FAQ