Calibration · PyPI cohort
How well does pkgxray call it?
An at-scale, code-only static scan of published packages, measured against a committed known-malware corpus. Four numbers, adjudicated by hand, reproducible from the inputs below.
Methodology & how to reproduce → · Raw JSON · Top-1000 target list
First PyPI-ecosystem calibration. The 1,000 most-downloaded PyPI projects, one static pass on the 1067b74 engine (a pre-release build targeting 1.1.0; the public npm release at run time was 1.0.5). Zero heuristic false blocks. Of the 4 blocks in the top-1000, 3 carry a known-CVE finding (OSV, by design) and 1 is a documented defensible true positive (fastmcp ships a live .claude/settings.json hooks config — an install-time-equivalent agent auto-exec surface). Catch rate is measured against a committed 5-sample reconstructed PyPI sdist-dropper corpus — a deliberately small denominator, reported as-is and not extrapolated to a population claim. 4 projects failed to resolve (yanked or renamed since the list snapshot) and are recorded as scan errors, never as blocks.
What the 1,000 counts: 1,000 top-1000 PyPI download-ranked list. Counted separately, not in this denominator: 5 reconstructed PyPI known-malware corpus.
Corrections
Published runs are immutable. If a number is wrong we publish a new dated run and note it here — we never silently edit a number in place. Contest a figure at the tracker.
No corrections to date.
Run history
Every published run stays up at a stable URL.
Pinned version: this page is the 2026-08-04-pypi snapshot at
pkgxray 1.0.6 · 1067b74. Engine 1.0.6 was a pre-release build, not published to npm (targets 1.1.0); the public npm release at run time was 1.0.5.
Latest run →