Package registryPyPI

A PyPI install runs setup.py before your code imports anything.

pip install executes setup.py. An import hook runs later, the first time you import the package. Extuno diffs every release, then puts both paths through static, dynamic, and AI analysis in a sandbox.

In shortTo check a PyPI package for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every PyPI release, then reports evidence on every finding.
PyPI - live inspectionexample
acme-http-client 2.31.0
pypi package
2.30.0->2.31.0
Static
Dynamic
AI
Analyzing update
What Extuno catches in PyPI

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

setup.py execution

Code in setup.py runs during pip install and reaches outside the package.

Critical
Diff finding

Typosquat payload

A near-name package carries an exfiltration routine in its import hook.

Critical
Diff finding

New install dependency

The release pulls an extra dependency that opens a network socket.

Review
See it on a poisoned update

Install-time code, caught before pip runs it

Extuno executes setup.py in a sandbox and records the network call it makes.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the package without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
your-service
acme-http-client 2.31.0
acme-numeric 1.26.4
flask 3.0.0
colorama-helper 0.0.3setup.py
colorama-helperpypi-stats.io

Scan your first PyPI package free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support PyPI?

Yes. Extuno scans PyPI with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan PyPI?

Extuno acquires the published PyPI artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in PyPI?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.