We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
Fuente:
arXiv
Saved in:
| Main Authors: | Spracklen, Joseph, Wijewickrama, Raveen, Sakib, A H M Nazmus, Maiti, Anindya, Viswanath, Bimal, Jadliwala, Murtuza |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Prompt and Circumstances: Evaluating the Efficacy of Human Prompt Inference in AI-Generated Art
by: Trinh, Khoi, et al.
Published: (2026)
by: Trinh, Khoi, et al.
Published: (2026)
NinjaDoH: A Censorship-Resistant Moving Target DoH Server Using Hyperscalers and IPNS
by: Seidenberger, Scott, et al.
Published: (2024)
by: Seidenberger, Scott, et al.
Published: (2024)
The WASM Cloak: Evaluating Browser Fingerprinting Defenses Under WebAssembly based Obfuscation
by: Sakib, A H M Nazmus, et al.
Published: (2025)
by: Sakib, A H M Nazmus, et al.
Published: (2025)
Promptly Yours? A Human Subject Study on Prompt Inference in AI-Generated Art
by: Trinh, Khoi, et al.
Published: (2024)
by: Trinh, Khoi, et al.
Published: (2024)
Unintentional Security Flaws in Code: Automated Defense via Root Cause Analysis
by: Islam, Nafis Tanveer, et al.
Published: (2024)
by: Islam, Nafis Tanveer, et al.
Published: (2024)
PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
by: Liu, Xiting, et al.
Published: (2026)
by: Liu, Xiting, et al.
Published: (2026)
A Static Analysis of Popular C Packages in Linux
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
How Far Have We Gone in Binary Code Understanding Using Large Language Models
by: Shang, Xiuwei, et al.
Published: (2024)
by: Shang, Xiuwei, et al.
Published: (2024)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
LLM Ghostbusters: Surgical Hallucination Suppression via Adaptive Unlearning
by: Spracklen, Joseph, et al.
Published: (2026)
by: Spracklen, Joseph, et al.
Published: (2026)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
by: Pohl, Timo, et al.
Published: (2025)
by: Pohl, Timo, et al.
Published: (2025)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
by: Simsek, Deniz, et al.
Published: (2025)
by: Simsek, Deniz, et al.
Published: (2025)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
ThermalTap: Passive Application Fingerprinting in VR Headsets via Thermal Side Channels
by: Akram, Mahsin Bin, et al.
Published: (2026)
by: Akram, Mahsin Bin, et al.
Published: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Does Teaming-Up LLMs Improve Secure Code Generation? A Comprehensive Evaluation with Multi-LLMSecCodeEval
by: Sabir, Bushra, et al.
Published: (2026)
by: Sabir, Bushra, et al.
Published: (2026)
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
by: Quan, Haowei, et al.
Published: (2025)
by: Quan, Haowei, et al.
Published: (2025)
VocalBridge: Latent Diffusion-Bridge Purification for Defeating Perturbation-Based Voiceprint Defenses
by: Abbasihafshejani, Maryam, et al.
Published: (2026)
by: Abbasihafshejani, Maryam, et al.
Published: (2026)
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
by: Ni, Ronghao, et al.
Published: (2025)
by: Ni, Ronghao, et al.
Published: (2025)
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
by: Li, Yu, et al.
Published: (2026)
by: Li, Yu, et al.
Published: (2026)
Developers Are Victims Too : A Comprehensive Analysis of The VS Code Extension Ecosystem
by: Edirimannage, Shehan, et al.
Published: (2024)
by: Edirimannage, Shehan, et al.
Published: (2024)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
by: Fang, Chongzhou, et al.
Published: (2023)
by: Fang, Chongzhou, et al.
Published: (2023)
Residual Risk Analysis in Benign Code: How Far Are We? A Multi-Model Semantic and Structural Similarity Approach
by: Farhad, Mohammad, et al.
Published: (2026)
by: Farhad, Mohammad, et al.
Published: (2026)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
by: Zhang, XiangRui, et al.
Published: (2025)
by: Zhang, XiangRui, et al.
Published: (2025)
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents?
by: Peng, Yibo, et al.
Published: (2025)
by: Peng, Yibo, et al.
Published: (2025)
Similar Items
-
Prompt and Circumstances: Evaluating the Efficacy of Human Prompt Inference in AI-Generated Art
by: Trinh, Khoi, et al.
Published: (2026) -
NinjaDoH: A Censorship-Resistant Moving Target DoH Server Using Hyperscalers and IPNS
by: Seidenberger, Scott, et al.
Published: (2024) -
The WASM Cloak: Evaluating Browser Fingerprinting Defenses Under WebAssembly based Obfuscation
by: Sakib, A H M Nazmus, et al.
Published: (2025) -
Promptly Yours? A Human Subject Study on Prompt Inference in AI-Generated Art
by: Trinh, Khoi, et al.
Published: (2024) -
Unintentional Security Flaws in Code: Automated Defense via Root Cause Analysis
by: Islam, Nafis Tanveer, et al.
Published: (2024)