Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
Fuente:
arXiv
Salvato in:
| Autori principali: | Zhang, Junan, Huang, Kaifeng, Huang, Yiheng, Chen, Bihuan, Wang, Ruisi, Wang, Chong, Peng, Xin |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2023
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
di: Toda, Takaaki, et al.
Pubblicazione: (2026)
di: Toda, Takaaki, et al.
Pubblicazione: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
di: Huang, Yiheng, et al.
Pubblicazione: (2026)
di: Huang, Yiheng, et al.
Pubblicazione: (2026)
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
di: Gao, Xingan, et al.
Pubblicazione: (2025)
di: Gao, Xingan, et al.
Pubblicazione: (2025)
A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
di: Samaana, Haya, et al.
Pubblicazione: (2024)
di: Samaana, Haya, et al.
Pubblicazione: (2024)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
di: Ibiyo, Motunrayo, et al.
Pubblicazione: (2025)
di: Ibiyo, Motunrayo, et al.
Pubblicazione: (2025)
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge Mapping
di: Huang, Cheng, et al.
Pubblicazione: (2024)
di: Huang, Cheng, et al.
Pubblicazione: (2024)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
di: Zeshan, Muhammad Umar, et al.
Pubblicazione: (2026)
di: Zeshan, Muhammad Umar, et al.
Pubblicazione: (2026)
An Analysis of Malicious Packages in Open-Source Software in the Wild
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
Analyzing the Accessibility of GitHub Repositories for PyPI and NPM Libraries
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2024)
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
eDySec: A Deep Learning-based Explainable Dynamic Analysis Framework for Detecting Malicious Packages in PyPI Ecosystem
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2026)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2026)
Malicious ML Model Detection by Learning Dynamic Behaviors
di: Nambiar, Sarang, et al.
Pubblicazione: (2026)
di: Nambiar, Sarang, et al.
Pubblicazione: (2026)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
di: Zhang, XiangRui, et al.
Pubblicazione: (2025)
di: Zhang, XiangRui, et al.
Pubblicazione: (2025)
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
di: Guo, Wenbo, et al.
Pubblicazione: (2026)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
di: Ryan, Ahmed, et al.
Pubblicazione: (2026)
di: Ryan, Ahmed, et al.
Pubblicazione: (2026)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
di: Huang, Youwei, et al.
Pubblicazione: (2025)
di: Huang, Youwei, et al.
Pubblicazione: (2025)
Taint-Based Code Slicing for LLMs-based Malicious NPM Package Detection
di: Nguyen, Dang-Khoa, et al.
Pubblicazione: (2025)
di: Nguyen, Dang-Khoa, et al.
Pubblicazione: (2025)
PyRadar: Towards Automatically Retrieving and Validating Source Code Repository Information for PyPI Packages
di: Gao, Kai, et al.
Pubblicazione: (2024)
di: Gao, Kai, et al.
Pubblicazione: (2024)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
di: Zhao, Jian, et al.
Pubblicazione: (2024)
di: Zhao, Jian, et al.
Pubblicazione: (2024)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
di: Ning, Kaiwen, et al.
Pubblicazione: (2024)
di: Ning, Kaiwen, et al.
Pubblicazione: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
di: Wang, Shenao, et al.
Pubblicazione: (2026)
di: Wang, Shenao, et al.
Pubblicazione: (2026)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
di: Masud, Md Rayhanul, et al.
Pubblicazione: (2024)
di: Masud, Md Rayhanul, et al.
Pubblicazione: (2024)
Analyzing the Usage of Donation Platforms for PyPI Libraries
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2025)
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2025)
MALSIGHT: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization
di: Lu, Haolang, et al.
Pubblicazione: (2024)
di: Lu, Haolang, et al.
Pubblicazione: (2024)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
di: Sun, Tiezhu, et al.
Pubblicazione: (2025)
di: Sun, Tiezhu, et al.
Pubblicazione: (2025)
Analyzing the Availability of E-Mail Addresses for PyPI Libraries
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2026)
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2026)
Less is More? An Empirical Study on Configuration Issues in Python PyPI Ecosystem
di: Peng, Yun, et al.
Pubblicazione: (2023)
di: Peng, Yun, et al.
Pubblicazione: (2023)
Cross-ecosystem categorization: A manual-curation protocol for the categorization of Java Maven libraries along Python PyPI Topics
di: Paramitha, Ranindya, et al.
Pubblicazione: (2024)
di: Paramitha, Ranindya, et al.
Pubblicazione: (2024)
JavaSith: A Client-Side Framework for Analyzing Potentially Malicious Extensions in Browsers, VS Code, and NPM Packages
di: Cohen, Avihay
Pubblicazione: (2025)
di: Cohen, Avihay
Pubblicazione: (2025)
Scam2Prompt: A Scalable Framework for Auditing Malicious Scam Endpoints in Production LLMs
di: Chen, Zhiyang, et al.
Pubblicazione: (2025)
di: Chen, Zhiyang, et al.
Pubblicazione: (2025)
Forecasting the Maintained Score from the OpenSSF Scorecard: A Study of GitHub Repositories Linked to PyPI Packages
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2026)
di: Tsakpinis, Alexandros, et al.
Pubblicazione: (2026)
Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
di: Termphaiboon, Chayanid, et al.
Pubblicazione: (2025)
di: Termphaiboon, Chayanid, et al.
Pubblicazione: (2025)
Malicious Package Detection using Metadata Information
di: Halder, S., et al.
Pubblicazione: (2024)
di: Halder, S., et al.
Pubblicazione: (2024)
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
di: Febriyanti, Indira, et al.
Pubblicazione: (2024)
di: Febriyanti, Indira, et al.
Pubblicazione: (2024)
Security Is Relative: Training-Free Vulnerability Detection via Multi-Agent Behavioral Contract Synthesis
di: Wang, Yongchao, et al.
Pubblicazione: (2026)
di: Wang, Yongchao, et al.
Pubblicazione: (2026)
Scalable and Precise Application-Centered Call Graph Construction for Python
di: Huang, Kaifeng, et al.
Pubblicazione: (2023)
di: Huang, Kaifeng, et al.
Pubblicazione: (2023)
Documenti analoghi
-
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
di: Toda, Takaaki, et al.
Pubblicazione: (2026) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
di: Guo, Wenbo, et al.
Pubblicazione: (2026) -
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025) -
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
di: Huang, Yiheng, et al.
Pubblicazione: (2026) -
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
di: Gao, Xingan, et al.
Pubblicazione: (2025)