Calibration · PyPI cohort

How well does pkgxray call it?

An at-scale, code-only static scan of published packages, measured against a committed known-malware corpus. Four numbers, adjudicated by hand, reproducible from the inputs below.

1,000
packages scanned
published PyPI packages (sdists), one static pass · source data
0.0%
false blocks, top 1,000
0 of the 1,000 most-downloaded packages · source data
100.0%
known-malware catch rate
5 of 5 corpus samples blocked outright · source data
2026-08-04
run date
pkgxray 1.0.6 · build 1067b74 · source data

First PyPI-ecosystem calibration. The 1,000 most-downloaded PyPI projects, one static pass on the 1067b74 engine (a pre-release build targeting 1.1.0; the public npm release at run time was 1.0.5). Zero heuristic false blocks. Of the 4 blocks in the top-1000, 3 carry a known-CVE finding (OSV, by design) and 1 is a documented defensible true positive (fastmcp ships a live .claude/settings.json hooks config — an install-time-equivalent agent auto-exec surface). Catch rate is measured against a committed 5-sample reconstructed PyPI sdist-dropper corpus — a deliberately small denominator, reported as-is and not extrapolated to a population claim. 4 projects failed to resolve (yanked or renamed since the list snapshot) and are recorded as scan errors, never as blocks.

What the 1,000 counts: 1,000 top-1000 PyPI download-ranked list. Counted separately, not in this denominator: 5 reconstructed PyPI known-malware corpus.

Corrections

Published runs are immutable. If a number is wrong we publish a new dated run and note it here — we never silently edit a number in place. Contest a figure at the tracker.

No corrections to date.

Run history

Every published run stays up at a stable URL.

Pinned version: this page is the 2026-08-04-pypi snapshot at pkgxray 1.0.6 · 1067b74. Engine 1.0.6 was a pre-release build, not published to npm (targets 1.1.0); the public npm release at run time was 1.0.5. Latest run →