ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
Fuente:
arXiv
Saved in:
| Main Authors: | Jiang, Wenxin, Çakar, Berk, Lysenko, Mikola, Davis, James C. |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
by: Li, Yu, et al.
Published: (2026)
by: Li, Yu, et al.
Published: (2026)
Towards the Systematic Testing of Regular Expression Engines
by: Çakar, Berk, et al.
Published: (2026)
by: Çakar, Berk, et al.
Published: (2026)
Towards a Benchmark for Dependency Decision-Making
by: Singla, Tanmay, et al.
Published: (2026)
by: Singla, Tanmay, et al.
Published: (2026)
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
by: Bhuiyan, Masudul Hasan Masud, et al.
Published: (2024)
by: Bhuiyan, Masudul Hasan Masud, et al.
Published: (2024)
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)
by: Improta, Cristina
Published: (2025)
LeakGuard: Detecting Memory Leaks Accurately and Scalably
by: Liang, Hongliang, et al.
Published: (2025)
by: Liang, Hongliang, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
LLM Security Guard for Code
by: Kavian, Arya, et al.
Published: (2024)
by: Kavian, Arya, et al.
Published: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
by: Koscinski, Viktoria, et al.
Published: (2025)
by: Koscinski, Viktoria, et al.
Published: (2025)
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
by: Štorek, Adam, et al.
Published: (2025)
by: Štorek, Adam, et al.
Published: (2025)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
by: Dong, Ben, et al.
Published: (2026)
by: Dong, Ben, et al.
Published: (2026)
Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
HighGuard: Cross-Chain Business Logic Monitoring of Smart Contracts
by: Eshghie, Mojtaba, et al.
Published: (2023)
by: Eshghie, Mojtaba, et al.
Published: (2023)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack Cascade
by: Cai, Bowen, et al.
Published: (2026)
by: Cai, Bowen, et al.
Published: (2026)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
A Static Analysis of Popular C Packages in Linux
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
by: Rahman, Md Nafiu, et al.
Published: (2026)
by: Rahman, Md Nafiu, et al.
Published: (2026)
DecipherGuard: Understanding and Deciphering Jailbreak Prompts for a Safer Deployment of Intelligent Software Systems
by: Yang, Rui, et al.
Published: (2025)
by: Yang, Rui, et al.
Published: (2025)
Automated Generation of Accurate Privacy Captions From Android Source Code Using Large Language Models
by: Jain, Vijayanta, et al.
Published: (2026)
by: Jain, Vijayanta, et al.
Published: (2026)
Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency
by: Joshi, Siddhant S., et al.
Published: (2024)
by: Joshi, Siddhant S., et al.
Published: (2024)
CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality Shift
by: Yu, Jiongchi, et al.
Published: (2025)
by: Yu, Jiongchi, et al.
Published: (2025)
Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts
by: Yang, Shuo, et al.
Published: (2024)
by: Yang, Shuo, et al.
Published: (2024)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
False Friends in the Shell: Unveiling the Emoticon Semantic Confusion in Large Language Models
by: Jiang, Weipeng, et al.
Published: (2026)
by: Jiang, Weipeng, et al.
Published: (2026)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
by: Pohl, Timo, et al.
Published: (2025)
by: Pohl, Timo, et al.
Published: (2025)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
by: Simsek, Deniz, et al.
Published: (2025)
by: Simsek, Deniz, et al.
Published: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
by: Ni, Ronghao, et al.
Published: (2026)
by: Ni, Ronghao, et al.
Published: (2026)
Smart Cuts: Enhance Active Learning for Vulnerability Detection by Pruning Hard-to-Learn Data
by: Lan, Xiang, et al.
Published: (2025)
by: Lan, Xiang, et al.
Published: (2025)
Similar Items
-
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
by: Li, Yu, et al.
Published: (2026) -
Towards the Systematic Testing of Regular Expression Engines
by: Çakar, Berk, et al.
Published: (2026) -
Towards a Benchmark for Dependency Decision-Making
by: Singla, Tanmay, et al.
Published: (2026) -
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
by: Bhuiyan, Masudul Hasan Masud, et al.
Published: (2024) -
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)