Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Masud, Md Rayhanul, Faloutsos, Michalis |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2024
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
On the effectiveness of Large Language Models for GitHub Workflows
von: Zhang, Xinyu, et al.
Veröffentlicht: (2024)
von: Zhang, Xinyu, et al.
Veröffentlicht: (2024)
Unpacking Security Scanners for GitHub Actions Workflows
von: Fares, Madjda, et al.
Veröffentlicht: (2026)
von: Fares, Madjda, et al.
Veröffentlicht: (2026)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
von: Ruan, Bonan, et al.
Veröffentlicht: (2026)
von: Ruan, Bonan, et al.
Veröffentlicht: (2026)
Exploring User Privacy Awareness on GitHub: An Empirical Study
von: Alfieri, Costanza, et al.
Veröffentlicht: (2024)
von: Alfieri, Costanza, et al.
Veröffentlicht: (2024)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
von: Asare, Owura, et al.
Veröffentlicht: (2022)
von: Asare, Owura, et al.
Veröffentlicht: (2022)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
von: Segal, Claudio, et al.
Veröffentlicht: (2026)
von: Segal, Claudio, et al.
Veröffentlicht: (2026)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
von: Rahman, Md Nafiu, et al.
Veröffentlicht: (2026)
von: Rahman, Md Nafiu, et al.
Veröffentlicht: (2026)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
von: Liu, Xueqing, et al.
Veröffentlicht: (2024)
von: Liu, Xueqing, et al.
Veröffentlicht: (2024)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
von: Fu, Yujia, et al.
Veröffentlicht: (2023)
von: Fu, Yujia, et al.
Veröffentlicht: (2023)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
von: Sharma, Anupam, et al.
Veröffentlicht: (2025)
von: Sharma, Anupam, et al.
Veröffentlicht: (2025)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
von: Siddiq, Mohammed Latif, et al.
Veröffentlicht: (2026)
von: Siddiq, Mohammed Latif, et al.
Veröffentlicht: (2026)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
von: Shifat, Fariha Tanjim, et al.
Veröffentlicht: (2026)
von: Shifat, Fariha Tanjim, et al.
Veröffentlicht: (2026)
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
von: He, Hao, et al.
Veröffentlicht: (2024)
von: He, Hao, et al.
Veröffentlicht: (2024)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
von: Naulty, John, et al.
Veröffentlicht: (2025)
von: Naulty, John, et al.
Veröffentlicht: (2025)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
von: Ferreyra, Nicolás E. Díaz, et al.
Veröffentlicht: (2026)
von: Ferreyra, Nicolás E. Díaz, et al.
Veröffentlicht: (2026)
Exposing Go's Hidden Bugs: A Novel Concolic Framework
von: Gorna, Karolina, et al.
Veröffentlicht: (2025)
von: Gorna, Karolina, et al.
Veröffentlicht: (2025)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
von: Zhao, Jian, et al.
Veröffentlicht: (2024)
von: Zhao, Jian, et al.
Veröffentlicht: (2024)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
von: Cipollone, Daniele, et al.
Veröffentlicht: (2025)
von: Cipollone, Daniele, et al.
Veröffentlicht: (2025)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
von: Ryan, Ahmed, et al.
Veröffentlicht: (2026)
von: Ryan, Ahmed, et al.
Veröffentlicht: (2026)
Classifying Issues in Open-source GitHub Repositories
von: Raaj, Amir Hossain, et al.
Veröffentlicht: (2025)
von: Raaj, Amir Hossain, et al.
Veröffentlicht: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
Malicious ML Model Detection by Learning Dynamic Behaviors
von: Nambiar, Sarang, et al.
Veröffentlicht: (2026)
von: Nambiar, Sarang, et al.
Veröffentlicht: (2026)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
von: Toda, Takaaki, et al.
Veröffentlicht: (2026)
von: Toda, Takaaki, et al.
Veröffentlicht: (2026)
PhaseSeed: Precise Call Graph Construction for Split-Phase Applications using Dynamic Seeding
von: Palit, Tapti, et al.
Veröffentlicht: (2025)
von: Palit, Tapti, et al.
Veröffentlicht: (2025)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
ReposVul: A Repository-Level High-Quality Vulnerability Dataset
von: Wang, Xinchen, et al.
Veröffentlicht: (2024)
von: Wang, Xinchen, et al.
Veröffentlicht: (2024)
Evolution of Log-Based Detection Rules in Public Repositories
von: Long, Minjun, et al.
Veröffentlicht: (2026)
von: Long, Minjun, et al.
Veröffentlicht: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
von: Liu, Shuhan, et al.
Veröffentlicht: (2025)
von: Liu, Shuhan, et al.
Veröffentlicht: (2025)
Exposing and Defending Membership Leakage in Vulnerability Prediction Models
von: Liao, Yihan, et al.
Veröffentlicht: (2025)
von: Liao, Yihan, et al.
Veröffentlicht: (2025)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
von: Ning, Kaiwen, et al.
Veröffentlicht: (2024)
von: Ning, Kaiwen, et al.
Veröffentlicht: (2024)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
von: Huang, Youwei, et al.
Veröffentlicht: (2025)
von: Huang, Youwei, et al.
Veröffentlicht: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
von: Sun, Tiezhu, et al.
Veröffentlicht: (2025)
von: Sun, Tiezhu, et al.
Veröffentlicht: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
von: Przymus, Piotr, et al.
Veröffentlicht: (2025)
von: Przymus, Piotr, et al.
Veröffentlicht: (2025)
SafeTrans: LLM-assisted Transpilation from C to Rust
von: Farrukh, Muhammad, et al.
Veröffentlicht: (2025)
von: Farrukh, Muhammad, et al.
Veröffentlicht: (2025)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
von: Dharmaadi, I Putu Arya, et al.
Veröffentlicht: (2025)
von: Dharmaadi, I Putu Arya, et al.
Veröffentlicht: (2025)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
von: Mehedi, Sk Tanzir, et al.
Veröffentlicht: (2025)
von: Mehedi, Sk Tanzir, et al.
Veröffentlicht: (2025)
RealSec-bench: A Benchmark for Evaluating Secure Code Generation in Real-World Repositories
von: Wang, Yanlin, et al.
Veröffentlicht: (2026)
von: Wang, Yanlin, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
On the effectiveness of Large Language Models for GitHub Workflows
von: Zhang, Xinyu, et al.
Veröffentlicht: (2024) -
Unpacking Security Scanners for GitHub Actions Workflows
von: Fares, Madjda, et al.
Veröffentlicht: (2026) -
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
von: Ruan, Bonan, et al.
Veröffentlicht: (2026) -
Exploring User Privacy Awareness on GitHub: An Empirical Study
von: Alfieri, Costanza, et al.
Veröffentlicht: (2024) -
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
von: Asare, Owura, et al.
Veröffentlicht: (2022)