Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
Fuente:
arXiv
Guardado en:
| Autores principales: | Zhang, Junan, Huang, Kaifeng, Huang, Yiheng, Chen, Bihuan, Wang, Ruisi, Wang, Chong, Peng, Xin |
|---|---|
| Formato: | Preprint |
| Publicado: |
2023
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
por: Toda, Takaaki, et al.
Publicado: (2026)
por: Toda, Takaaki, et al.
Publicado: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
por: Guo, Wenbo, et al.
Publicado: (2026)
por: Guo, Wenbo, et al.
Publicado: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
por: Mehedi, Sk Tanzir, et al.
Publicado: (2025)
por: Mehedi, Sk Tanzir, et al.
Publicado: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
por: Huang, Yiheng, et al.
Publicado: (2026)
por: Huang, Yiheng, et al.
Publicado: (2026)
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
por: Gao, Xingan, et al.
Publicado: (2025)
por: Gao, Xingan, et al.
Publicado: (2025)
A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
por: Samaana, Haya, et al.
Publicado: (2024)
por: Samaana, Haya, et al.
Publicado: (2024)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
por: Ibiyo, Motunrayo, et al.
Publicado: (2025)
por: Ibiyo, Motunrayo, et al.
Publicado: (2025)
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
por: Montaruli, Biagio, et al.
Publicado: (2025)
por: Montaruli, Biagio, et al.
Publicado: (2025)
DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge Mapping
por: Huang, Cheng, et al.
Publicado: (2024)
por: Huang, Cheng, et al.
Publicado: (2024)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
por: Zeshan, Muhammad Umar, et al.
Publicado: (2026)
por: Zeshan, Muhammad Umar, et al.
Publicado: (2026)
An Analysis of Malicious Packages in Open-Source Software in the Wild
por: Zhou, Xiaoyan, et al.
Publicado: (2024)
por: Zhou, Xiaoyan, et al.
Publicado: (2024)
Analyzing the Accessibility of GitHub Repositories for PyPI and NPM Libraries
por: Tsakpinis, Alexandros, et al.
Publicado: (2024)
por: Tsakpinis, Alexandros, et al.
Publicado: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
por: Montaruli, Biagio, et al.
Publicado: (2025)
por: Montaruli, Biagio, et al.
Publicado: (2025)
eDySec: A Deep Learning-based Explainable Dynamic Analysis Framework for Detecting Malicious Packages in PyPI Ecosystem
por: Mehedi, Sk Tanzir, et al.
Publicado: (2026)
por: Mehedi, Sk Tanzir, et al.
Publicado: (2026)
Malicious ML Model Detection by Learning Dynamic Behaviors
por: Nambiar, Sarang, et al.
Publicado: (2026)
por: Nambiar, Sarang, et al.
Publicado: (2026)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
por: Guo, Wenbo, et al.
Publicado: (2026)
por: Guo, Wenbo, et al.
Publicado: (2026)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
por: Zhang, XiangRui, et al.
Publicado: (2025)
por: Zhang, XiangRui, et al.
Publicado: (2025)
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
por: Guo, Wenbo, et al.
Publicado: (2026)
por: Guo, Wenbo, et al.
Publicado: (2026)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
por: Ryan, Ahmed, et al.
Publicado: (2026)
por: Ryan, Ahmed, et al.
Publicado: (2026)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
por: Huang, Youwei, et al.
Publicado: (2025)
por: Huang, Youwei, et al.
Publicado: (2025)
Taint-Based Code Slicing for LLMs-based Malicious NPM Package Detection
por: Nguyen, Dang-Khoa, et al.
Publicado: (2025)
por: Nguyen, Dang-Khoa, et al.
Publicado: (2025)
PyRadar: Towards Automatically Retrieving and Validating Source Code Repository Information for PyPI Packages
por: Gao, Kai, et al.
Publicado: (2024)
por: Gao, Kai, et al.
Publicado: (2024)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
por: Zhao, Jian, et al.
Publicado: (2024)
por: Zhao, Jian, et al.
Publicado: (2024)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
por: Ning, Kaiwen, et al.
Publicado: (2024)
por: Ning, Kaiwen, et al.
Publicado: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
por: Wang, Shenao, et al.
Publicado: (2026)
por: Wang, Shenao, et al.
Publicado: (2026)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
Analyzing the Usage of Donation Platforms for PyPI Libraries
por: Tsakpinis, Alexandros, et al.
Publicado: (2025)
por: Tsakpinis, Alexandros, et al.
Publicado: (2025)
MALSIGHT: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization
por: Lu, Haolang, et al.
Publicado: (2024)
por: Lu, Haolang, et al.
Publicado: (2024)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
por: Sun, Tiezhu, et al.
Publicado: (2025)
por: Sun, Tiezhu, et al.
Publicado: (2025)
Analyzing the Availability of E-Mail Addresses for PyPI Libraries
por: Tsakpinis, Alexandros, et al.
Publicado: (2026)
por: Tsakpinis, Alexandros, et al.
Publicado: (2026)
Less is More? An Empirical Study on Configuration Issues in Python PyPI Ecosystem
por: Peng, Yun, et al.
Publicado: (2023)
por: Peng, Yun, et al.
Publicado: (2023)
Cross-ecosystem categorization: A manual-curation protocol for the categorization of Java Maven libraries along Python PyPI Topics
por: Paramitha, Ranindya, et al.
Publicado: (2024)
por: Paramitha, Ranindya, et al.
Publicado: (2024)
JavaSith: A Client-Side Framework for Analyzing Potentially Malicious Extensions in Browsers, VS Code, and NPM Packages
por: Cohen, Avihay
Publicado: (2025)
por: Cohen, Avihay
Publicado: (2025)
Scam2Prompt: A Scalable Framework for Auditing Malicious Scam Endpoints in Production LLMs
por: Chen, Zhiyang, et al.
Publicado: (2025)
por: Chen, Zhiyang, et al.
Publicado: (2025)
Forecasting the Maintained Score from the OpenSSF Scorecard: A Study of GitHub Repositories Linked to PyPI Packages
por: Tsakpinis, Alexandros, et al.
Publicado: (2026)
por: Tsakpinis, Alexandros, et al.
Publicado: (2026)
Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
por: Termphaiboon, Chayanid, et al.
Publicado: (2025)
por: Termphaiboon, Chayanid, et al.
Publicado: (2025)
Malicious Package Detection using Metadata Information
por: Halder, S., et al.
Publicado: (2024)
por: Halder, S., et al.
Publicado: (2024)
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
por: Febriyanti, Indira, et al.
Publicado: (2024)
por: Febriyanti, Indira, et al.
Publicado: (2024)
Security Is Relative: Training-Free Vulnerability Detection via Multi-Agent Behavioral Contract Synthesis
por: Wang, Yongchao, et al.
Publicado: (2026)
por: Wang, Yongchao, et al.
Publicado: (2026)
Scalable and Precise Application-Centered Call Graph Construction for Python
por: Huang, Kaifeng, et al.
Publicado: (2023)
por: Huang, Kaifeng, et al.
Publicado: (2023)
Ejemplares similares
-
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
por: Toda, Takaaki, et al.
Publicado: (2026) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
por: Guo, Wenbo, et al.
Publicado: (2026) -
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
por: Mehedi, Sk Tanzir, et al.
Publicado: (2025) -
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
por: Huang, Yiheng, et al.
Publicado: (2026) -
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
por: Gao, Xingan, et al.
Publicado: (2025)