Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
Fuente:
arXiv
Saved in:
| Main Authors: | Swierzy, Ben, Ohm, Marc, Meier, Michael |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
by: Pohl, Timo, et al.
Published: (2025)
by: Pohl, Timo, et al.
Published: (2025)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
by: Fei, Qingyuan, et al.
Published: (2025)
by: Fei, Qingyuan, et al.
Published: (2025)
CASCADE: LLM-Powered JavaScript Deobfuscator at Google
by: Jiang, Shan, et al.
Published: (2025)
by: Jiang, Shan, et al.
Published: (2025)
Characterizing JavaScript Security Code Smells
by: Kambhampati, Vikas, et al.
Published: (2024)
by: Kambhampati, Vikas, et al.
Published: (2024)
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026)
by: Zhang, Lingming, et al.
Published: (2026)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
by: Schott, Stefan, et al.
Published: (2025)
by: Schott, Stefan, et al.
Published: (2025)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Automatic Attack Script Generation: a MDA Approach
by: Goux, Quentin, et al.
Published: (2026)
by: Goux, Quentin, et al.
Published: (2026)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
by: Simsek, Deniz, et al.
Published: (2025)
by: Simsek, Deniz, et al.
Published: (2025)
What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
by: Niu, Yuqing, et al.
Published: (2025)
by: Niu, Yuqing, et al.
Published: (2025)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
by: Schmid, Larissa, et al.
Published: (2025)
by: Schmid, Larissa, et al.
Published: (2025)
PPT4J: Patch Presence Test for Java Binaries
by: Pan, Zhiyuan, et al.
Published: (2023)
by: Pan, Zhiyuan, et al.
Published: (2023)
PowerPeeler: A Precise and General Dynamic Deobfuscation Method for PowerShell Scripts
by: Li, Ruijie, et al.
Published: (2024)
by: Li, Ruijie, et al.
Published: (2024)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
Coverage-Guided Multi-Agent Harness Generation for Java Library Fuzzing
by: Loose, Nils, et al.
Published: (2026)
by: Loose, Nils, et al.
Published: (2026)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
A Static Analysis of Popular C Packages in Linux
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
State Machine Model for The Update Framework (TUF)
by: Romansky, Brian, et al.
Published: (2025)
by: Romansky, Brian, et al.
Published: (2025)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
by: Liu, Xiting, et al.
Published: (2026)
by: Liu, Xiting, et al.
Published: (2026)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
Similar Items
-
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
by: Swierzy, Ben, et al.
Published: (2025) -
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
by: Pohl, Timo, et al.
Published: (2025) -
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023) -
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025) -
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)