You Can Run But You Can't Hide: Runtime Protection Against Malicious Package Updates For Node.js
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Ohm, Marc, Pohl, Timo, Boes, Felix |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2023
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
von: Cornelissen, Eric, et al.
Veröffentlicht: (2025)
von: Cornelissen, Eric, et al.
Veröffentlicht: (2025)
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
von: Ni, Ronghao, et al.
Veröffentlicht: (2025)
von: Ni, Ronghao, et al.
Veröffentlicht: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
von: Ni, Ronghao, et al.
Veröffentlicht: (2026)
von: Ni, Ronghao, et al.
Veröffentlicht: (2026)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
von: Pohl, Timo, et al.
Veröffentlicht: (2025)
von: Pohl, Timo, et al.
Veröffentlicht: (2025)
You Can't Steal Nothing: Mitigating Prompt Leakages in LLMs via System Vectors
von: Cao, Bochuan, et al.
Veröffentlicht: (2025)
von: Cao, Bochuan, et al.
Veröffentlicht: (2025)
Triosecuris: Formally Verified Protection Against Speculative Control-Flow Hijacking
von: Baumann, Jonathan, et al.
Veröffentlicht: (2026)
von: Baumann, Jonathan, et al.
Veröffentlicht: (2026)
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
von: Mai, Wuyuao, et al.
Veröffentlicht: (2025)
von: Mai, Wuyuao, et al.
Veröffentlicht: (2025)
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
Theorem-Carrying Transactions: Runtime Verification to Ensure Interface Specifications for Smart Contract Safety
von: Ball, Thomas, et al.
Veröffentlicht: (2024)
von: Ball, Thomas, et al.
Veröffentlicht: (2024)
Reformulation is All You Need: Addressing Malicious Text Features in DNNs
von: Jiang, Yi, et al.
Veröffentlicht: (2025)
von: Jiang, Yi, et al.
Veröffentlicht: (2025)
You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager
von: Mertens, Gilles, et al.
Veröffentlicht: (2023)
von: Mertens, Gilles, et al.
Veröffentlicht: (2023)
Thwart Me If You Can: An Empirical Analysis of Android Platform Armoring Against Stalkerware
von: Jadhav, Malvika, et al.
Veröffentlicht: (2025)
von: Jadhav, Malvika, et al.
Veröffentlicht: (2025)
Malicious and Unintentional Disclosure Risks in Large Language Models for Code Generation
von: Rabin, Rafiqul, et al.
Veröffentlicht: (2025)
von: Rabin, Rafiqul, et al.
Veröffentlicht: (2025)
Have You Merged My Model? On The Robustness of Large Language Model IP Protection Methods Against Model Merging
von: Cong, Tianshuo, et al.
Veröffentlicht: (2024)
von: Cong, Tianshuo, et al.
Veröffentlicht: (2024)
HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware Tracing
von: Zhang, Yiyu, et al.
Veröffentlicht: (2024)
von: Zhang, Yiyu, et al.
Veröffentlicht: (2024)
OverrideFuzz: Semantic-Aware Grammar Fuzzing for Script-Runtime Vulnerabilities
von: Qiu, Yiran
Veröffentlicht: (2026)
von: Qiu, Yiran
Veröffentlicht: (2026)
You Can Backdoor Personalized Federated Learning
von: Ye, Tiandi, et al.
Veröffentlicht: (2023)
von: Ye, Tiandi, et al.
Veröffentlicht: (2023)
Hornet Node and the Hornet DSL: A Minimal, Executable Specification for Bitcoin Consensus
von: Sharp, Toby
Veröffentlicht: (2025)
von: Sharp, Toby
Veröffentlicht: (2025)
BaxBench: Can LLMs Generate Correct and Secure Backends?
von: Vero, Mark, et al.
Veröffentlicht: (2025)
von: Vero, Mark, et al.
Veröffentlicht: (2025)
Batch Me If You Can: Coverage-guided RPKI Fuzzing at Scale
von: Schulmann, Haya, et al.
Veröffentlicht: (2026)
von: Schulmann, Haya, et al.
Veröffentlicht: (2026)
Can You Tell It's AI? Human Perception of Synthetic Voices in Vishing Scenarios
von: Bhatti, Zoha Hayat, et al.
Veröffentlicht: (2026)
von: Bhatti, Zoha Hayat, et al.
Veröffentlicht: (2026)
Demo: TOSense -- What Did You Just Agree to?
von: Chen, Xinzhang, et al.
Veröffentlicht: (2025)
von: Chen, Xinzhang, et al.
Veröffentlicht: (2025)
From Description to Score: Can LLMs Quantify Vulnerabilities?
von: Jafarikhah, Sima, et al.
Veröffentlicht: (2025)
von: Jafarikhah, Sima, et al.
Veröffentlicht: (2025)
Now You Hear Me: Audio Narrative Attacks Against Large Audio-Language Models
von: Yu, Ye, et al.
Veröffentlicht: (2026)
von: Yu, Ye, et al.
Veröffentlicht: (2026)
Are You Getting What You Pay For? Auditing Model Substitution in LLM APIs
von: Cai, Will, et al.
Veröffentlicht: (2025)
von: Cai, Will, et al.
Veröffentlicht: (2025)
You Can Use But Cannot Recognize: Preserving Visual Privacy in Deep Neural Networks
von: Li, Qiushi, et al.
Veröffentlicht: (2024)
von: Li, Qiushi, et al.
Veröffentlicht: (2024)
Why Neural Structural Obfuscation Can't Kill White-Box Watermarks for Good!
von: Jiang, Yanna, et al.
Veröffentlicht: (2026)
von: Jiang, Yanna, et al.
Veröffentlicht: (2026)
SPML: A DSL for Defending Language Models Against Prompt Attacks
von: Sharma, Reshabh K, et al.
Veröffentlicht: (2024)
von: Sharma, Reshabh K, et al.
Veröffentlicht: (2024)
Malicious Package Detection using Metadata Information
von: Halder, S., et al.
Veröffentlicht: (2024)
von: Halder, S., et al.
Veröffentlicht: (2024)
Preventing Jailbreak Prompts as Malicious Tools for Cybercriminals: A Cyber Defense Perspective
von: Tshimula, Jean Marie, et al.
Veröffentlicht: (2024)
von: Tshimula, Jean Marie, et al.
Veröffentlicht: (2024)
RunPBA -- Runtime attestation for microcontrollers with PACBTI
von: Cirne, André, et al.
Veröffentlicht: (2025)
von: Cirne, André, et al.
Veröffentlicht: (2025)
LLMs, You Can Evaluate It! Design of Multi-perspective Report Evaluation for Security Operation Centers
von: Okada, Hiroyuki, et al.
Veröffentlicht: (2026)
von: Okada, Hiroyuki, et al.
Veröffentlicht: (2026)
Verify Before You Fix: Agentic Execution Grounding for Trustworthy Cross-Language Code Analysis
von: Gajjar, Jugal
Veröffentlicht: (2026)
von: Gajjar, Jugal
Veröffentlicht: (2026)
Look Twice before You Leap: A Rational Framework for Localized Adversarial Anonymization
von: Duan, Donghang, et al.
Veröffentlicht: (2025)
von: Duan, Donghang, et al.
Veröffentlicht: (2025)
Formalizing, Verifying and Applying ISA Security Guarantees as Universal Contracts
von: Huyghebaert, Sander, et al.
Veröffentlicht: (2023)
von: Huyghebaert, Sander, et al.
Veröffentlicht: (2023)
Taypsi: Static Enforcement of Privacy Policies for Policy-Agnostic Oblivious Computation
von: Ye, Qianchuan, et al.
Veröffentlicht: (2023)
von: Ye, Qianchuan, et al.
Veröffentlicht: (2023)
OblivIO: Securing reactive programs by oblivious execution with bounded traffic overheads
von: Blaabjerg, Jeppe Fredsgaard, et al.
Veröffentlicht: (2023)
von: Blaabjerg, Jeppe Fredsgaard, et al.
Veröffentlicht: (2023)
Secure Composition of Robust and Optimising Compilers
von: Kruse, Matthis, et al.
Veröffentlicht: (2023)
von: Kruse, Matthis, et al.
Veröffentlicht: (2023)
Graded Modal Types for Integrity and Confidentiality
von: Marshall, Danielle, et al.
Veröffentlicht: (2023)
von: Marshall, Danielle, et al.
Veröffentlicht: (2023)
Ähnliche Einträge
-
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
von: Cornelissen, Eric, et al.
Veröffentlicht: (2025) -
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
von: Ni, Ronghao, et al.
Veröffentlicht: (2025) -
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
von: Ni, Ronghao, et al.
Veröffentlicht: (2026) -
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
von: Pohl, Timo, et al.
Veröffentlicht: (2025) -
You Can't Steal Nothing: Mitigating Prompt Leakages in LLMs via System Vectors
von: Cao, Bochuan, et al.
Veröffentlicht: (2025)