Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
Fuente:
arXiv
Saved in:
| Main Authors: | Guo, Wenbo, Liu, Chengwei, Kang, Ming, Zhang, Yiran, Wu, Jiahui, Xu, Zhengzi, Sachidananda, Vinay, Liu, Yang |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
by: Gao, Xingan, et al.
Published: (2025)
by: Gao, Xingan, et al.
Published: (2025)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
eDySec: A Deep Learning-based Explainable Dynamic Analysis Framework for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2026)
by: Mehedi, Sk Tanzir, et al.
Published: (2026)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
by: Samaana, Haya, et al.
Published: (2024)
by: Samaana, Haya, et al.
Published: (2024)
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
by: Guo, Wenbo, et al.
Published: (2024)
by: Guo, Wenbo, et al.
Published: (2024)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
by: Ibiyo, Motunrayo, et al.
Published: (2025)
by: Ibiyo, Motunrayo, et al.
Published: (2025)
Malicious ML Model Detection by Learning Dynamic Behaviors
by: Nambiar, Sarang, et al.
Published: (2026)
by: Nambiar, Sarang, et al.
Published: (2026)
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
by: Li, Yu, et al.
Published: (2026)
by: Li, Yu, et al.
Published: (2026)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
by: Zhang, XiangRui, et al.
Published: (2025)
by: Zhang, XiangRui, et al.
Published: (2025)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
by: Huang, Youwei, et al.
Published: (2025)
by: Huang, Youwei, et al.
Published: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis
by: Sun, Yuqiang, et al.
Published: (2023)
by: Sun, Yuqiang, et al.
Published: (2023)
Cross-ecosystem categorization: A manual-curation protocol for the categorization of Java Maven libraries along Python PyPI Topics
by: Paramitha, Ranindya, et al.
Published: (2024)
by: Paramitha, Ranindya, et al.
Published: (2024)
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners
by: Shi, Jingyi, et al.
Published: (2025)
by: Shi, Jingyi, et al.
Published: (2025)
PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
by: Liu, Xiting, et al.
Published: (2026)
by: Liu, Xiting, et al.
Published: (2026)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
Smart Cuts: Enhance Active Learning for Vulnerability Detection by Pruning Hard-to-Learn Data
by: Lan, Xiang, et al.
Published: (2025)
by: Lan, Xiang, et al.
Published: (2025)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
by: Ning, Kaiwen, et al.
Published: (2024)
by: Ning, Kaiwen, et al.
Published: (2024)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
An Empirical Study of Vulnerability Detection using Federated Learning
by: Zhou, Peiheng, et al.
Published: (2024)
by: Zhou, Peiheng, et al.
Published: (2024)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
by: Sun, Tiezhu, et al.
Published: (2025)
by: Sun, Tiezhu, et al.
Published: (2025)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
Cross-Inlining Binary Function Similarity Detection
by: Jia, Ang, et al.
Published: (2024)
by: Jia, Ang, et al.
Published: (2024)
BandFuzz: An ML-powered Collaborative Fuzzing Framework
by: Shi, Wenxuan, et al.
Published: (2025)
by: Shi, Wenxuan, et al.
Published: (2025)
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
by: Quan, Haowei, et al.
Published: (2025)
by: Quan, Haowei, et al.
Published: (2025)
MARD: A Multi-Agent Framework for Robust Android Malware Detection
by: Zeng, Xueying, et al.
Published: (2026)
by: Zeng, Xueying, et al.
Published: (2026)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025)
by: Yang, Yanjing, et al.
Published: (2025)
Similar Items
-
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026) -
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026) -
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025) -
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023) -
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
by: Gao, Xingan, et al.
Published: (2025)