A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
Fuente:
arXiv
Saved in:
| Main Authors: | Samaana, Haya, Costa, Diego Elias, Shihab, Emad, Abdellatif, Ahmad |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Opportunities and Security Risks of Technical Leverage: A Replication Study on the NPM Ecosystem
by: Samaana, Haya, et al.
Published: (2024)
by: Samaana, Haya, et al.
Published: (2024)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
The Impact of Environment Configurations on the Stability of AI-Enabled Systems
by: Rahman, Musfiqur, et al.
Published: (2024)
by: Rahman, Musfiqur, et al.
Published: (2024)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
by: Ibiyo, Motunrayo, et al.
Published: (2025)
by: Ibiyo, Motunrayo, et al.
Published: (2025)
A Transformer-based Approach for Augmenting Software Engineering Chatbots Datasets
by: Abdellatif, Ahmad, et al.
Published: (2024)
by: Abdellatif, Ahmad, et al.
Published: (2024)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
PyRadar: Towards Automatically Retrieving and Validating Source Code Repository Information for PyPI Packages
by: Gao, Kai, et al.
Published: (2024)
by: Gao, Kai, et al.
Published: (2024)
Predicting the First Response Latency of Maintainers and Contributors in Pull Requests
by: Khatoonabadi, SayedHassan, et al.
Published: (2023)
by: Khatoonabadi, SayedHassan, et al.
Published: (2023)
Analyzing the Usage of Donation Platforms for PyPI Libraries
by: Tsakpinis, Alexandros, et al.
Published: (2025)
by: Tsakpinis, Alexandros, et al.
Published: (2025)
Analyzing the Availability of E-Mail Addresses for PyPI Libraries
by: Tsakpinis, Alexandros, et al.
Published: (2026)
by: Tsakpinis, Alexandros, et al.
Published: (2026)
Analyzing the Accessibility of GitHub Repositories for PyPI and NPM Libraries
by: Tsakpinis, Alexandros, et al.
Published: (2024)
by: Tsakpinis, Alexandros, et al.
Published: (2024)
Forecasting the Maintained Score from the OpenSSF Scorecard: A Study of GitHub Repositories Linked to PyPI Packages
by: Tsakpinis, Alexandros, et al.
Published: (2026)
by: Tsakpinis, Alexandros, et al.
Published: (2026)
Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
by: Termphaiboon, Chayanid, et al.
Published: (2025)
by: Termphaiboon, Chayanid, et al.
Published: (2025)
Less is More? An Empirical Study on Configuration Issues in Python PyPI Ecosystem
by: Peng, Yun, et al.
Published: (2023)
by: Peng, Yun, et al.
Published: (2023)
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
by: Febriyanti, Indira, et al.
Published: (2024)
by: Febriyanti, Indira, et al.
Published: (2024)
Small Changes, Big Trouble: Demystifying and Parsing License Variants for Incompatibility Detection in the PyPI Ecosystem
by: Xu, Weiwei, et al.
Published: (2025)
by: Xu, Weiwei, et al.
Published: (2025)
Automatic Detection of LLM-Generated Code: A Comparative Case Study of Contemporary Models Across Function and Class Granularities
by: Rahman, Musfiqur, et al.
Published: (2024)
by: Rahman, Musfiqur, et al.
Published: (2024)
An Approach for Auto Generation of Labeling Functions for Software Engineering Chatbots
by: Alor, Ebube, et al.
Published: (2024)
by: Alor, Ebube, et al.
Published: (2024)
Investigating Notable Metadata Practices in PyPI Libraries: An Empirical Study about Repository and Donation Platform URLs
by: Tsakpinis, Alexandros, et al.
Published: (2026)
by: Tsakpinis, Alexandros, et al.
Published: (2026)
Modeling Dependency-Propagated Ecosystem Impact of Changes in Maintenance Activities: Evaluating Support Strategies in the PyPI Network
by: Tsakpinis, Alexandros, et al.
Published: (2026)
by: Tsakpinis, Alexandros, et al.
Published: (2026)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
Is ChatGPT a Good Software Librarian? An Exploratory Study on the Use of ChatGPT for Software Library Recommendations
by: Latendresse, Jasmine, et al.
Published: (2024)
by: Latendresse, Jasmine, et al.
Published: (2024)
The Impact of Large Language Models (LLMs) on Code Review Process
by: Collante, Antonio, et al.
Published: (2025)
by: Collante, Antonio, et al.
Published: (2025)
On Wasted Contributions: Understanding the Dynamics of Contributor-Abandoned Pull Requests
by: Khatoonabadi, SayedHassan, et al.
Published: (2021)
by: Khatoonabadi, SayedHassan, et al.
Published: (2021)
Understanding the Helpfulness of Stale Bot for Pull-based Development: An Empirical Study of 20 Large Open-Source Projects
by: Khatoonabadi, SayedHassan, et al.
Published: (2023)
by: Khatoonabadi, SayedHassan, et al.
Published: (2023)
Will It Survive? Deciphering the Fate of AI-Generated Code in Open Source
by: Rahman, Musfiqur, et al.
Published: (2026)
by: Rahman, Musfiqur, et al.
Published: (2026)
MLmisFinder: A Specification and Detection Approach of Machine Learning Service Misuses
by: Amor, Hadil Ben, et al.
Published: (2026)
by: Amor, Hadil Ben, et al.
Published: (2026)
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
SafePyScript: A Web-Based Solution for Machine Learning-Driven Vulnerability Detection in Python
by: Farasat, Talaya, et al.
Published: (2024)
by: Farasat, Talaya, et al.
Published: (2024)
Automated File-Level Logging Generation for Machine Learning Applications using LLMs: A Case Study using GPT-4o Mini
by: Rodriguez, Mayra Sofia Ruiz, et al.
Published: (2025)
by: Rodriguez, Mayra Sofia Ruiz, et al.
Published: (2025)
Tracing Vulnerabilities in Maven: A Study of CVE lifecycles and Dependency Networks
by: Yang-Smith, Corey, et al.
Published: (2025)
by: Yang-Smith, Corey, et al.
Published: (2025)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Evaluating the Use of LLMs for Automated DOM-Level Resolution of Web Performance Issues
by: Peters, Gideon, et al.
Published: (2026)
by: Peters, Gideon, et al.
Published: (2026)
PyGen: A Collaborative Human-AI Approach to Python Package Creation
by: Barua, Saikat, et al.
Published: (2024)
by: Barua, Saikat, et al.
Published: (2024)
Towards Supporting Open Source Library Maintainers with Community-Based Analytics
by: Raj, Rachna, et al.
Published: (2025)
by: Raj, Rachna, et al.
Published: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Synergizing LLMs and Knowledge Graphs: A Novel Approach to Software Repository-Related Question Answering
by: Abedu, Samuel, et al.
Published: (2024)
by: Abedu, Samuel, et al.
Published: (2024)
Similar Items
-
Opportunities and Security Risks of Technical Leverage: A Replication Study on the NPM Ecosystem
by: Samaana, Haya, et al.
Published: (2024) -
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026) -
The Impact of Environment Configurations on the Stability of AI-Enabled Systems
by: Rahman, Musfiqur, et al.
Published: (2024) -
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025) -
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
by: Ibiyo, Motunrayo, et al.
Published: (2025)