Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
Fuente:
arXiv
Saved in:
| Main Authors: | Guo, Wenbo, Chen, Zhongwen, Xu, Zhengzi, Liu, Chengwei, Kang, Ming, Song, Shiwen, Liu, Chengyue, Xu, Yijia, Sun, Weisong, Liu, Yang |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
by: Guo, Wenbo, et al.
Published: (2024)
by: Guo, Wenbo, et al.
Published: (2024)
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
by: Tang, Wei, et al.
Published: (2024)
by: Tang, Wei, et al.
Published: (2024)
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
by: Zhang, Lyuye, et al.
Published: (2025)
by: Zhang, Lyuye, et al.
Published: (2025)
ModuleGuard:Understanding and Detecting Module Conflicts in Python Ecosystem
by: Zhu, Ruofan, et al.
Published: (2024)
by: Zhu, Ruofan, et al.
Published: (2024)
Doctor: Optimizing Container Rebuild Efficiency by Instruction Re-Orchestration
by: Zhu, Zhiling, et al.
Published: (2025)
by: Zhu, Zhiling, et al.
Published: (2025)
Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem
by: Tevarut, Napasorn, et al.
Published: (2025)
by: Tevarut, Napasorn, et al.
Published: (2025)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
JC-Finder: Detecting Java Clone-based Third-Party Library by Class-level Tree Analysis
by: Zhao, Lida, et al.
Published: (2025)
by: Zhao, Lida, et al.
Published: (2025)
Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
by: Hu, Jinchang, et al.
Published: (2023)
by: Hu, Jinchang, et al.
Published: (2023)
What About Our Bug? A Study on the Responsiveness of NPM Package Maintainers
by: Saeidi, Mohammadreza, et al.
Published: (2025)
by: Saeidi, Mohammadreza, et al.
Published: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Hallucination Detection for LLM-based Text-to-SQL Generation via Two-Stage Metamorphic Testing
by: Yang, Bo, et al.
Published: (2025)
by: Yang, Bo, et al.
Published: (2025)
A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
by: Samaana, Haya, et al.
Published: (2024)
by: Samaana, Haya, et al.
Published: (2024)
Towards Better Comprehension of Breaking Changes in the NPM Ecosystem
by: Kong, Dezhen, et al.
Published: (2024)
by: Kong, Dezhen, et al.
Published: (2024)
UCRBench: Benchmarking LLMs on Use Case Recovery
by: Xiao, Shuyuan, et al.
Published: (2025)
by: Xiao, Shuyuan, et al.
Published: (2025)
Scaling Test-Driven Code Generation from Functions to Classes: An Empirical Study
by: Liang, Yunhao, et al.
Published: (2026)
by: Liang, Yunhao, et al.
Published: (2026)
Requirements Development and Formalization for Reliable Code Generation: A Multi-Agent Vision
by: Lu, Xu, et al.
Published: (2025)
by: Lu, Xu, et al.
Published: (2025)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
by: Ibiyo, Motunrayo, et al.
Published: (2025)
by: Ibiyo, Motunrayo, et al.
Published: (2025)
Evolaris: A Roadmap to Self-Evolving Software Intelligence Management
by: Liu, Chengwei, et al.
Published: (2025)
by: Liu, Chengwei, et al.
Published: (2025)
GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis
by: Sun, Yuqiang, et al.
Published: (2023)
by: Sun, Yuqiang, et al.
Published: (2023)
Enhancing and Reporting Robustness Boundary of Neural Code Models for Intelligent Code Understanding
by: Han, Tingxu, et al.
Published: (2026)
by: Han, Tingxu, et al.
Published: (2026)
Enhancing Function Name Prediction using Votes-Based Name Tokenization and Multi-Task Learning
by: Zhang, Xiaoling, et al.
Published: (2024)
by: Zhang, Xiaoling, et al.
Published: (2024)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
by: Zeshan, Muhammad Umar, et al.
Published: (2026)
iReDev: A Knowledge-Driven Multi-Agent Framework for Intelligent Requirements Development
by: Jin, Dongming, et al.
Published: (2025)
by: Jin, Dongming, et al.
Published: (2025)
Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
by: Liu, Yi, et al.
Published: (2023)
by: Liu, Yi, et al.
Published: (2023)
SkillClone: Multi-Modal Clone Detection and Clone Propagation Analysis in the Agent Skill Ecosystem
by: Zhu, Jiaying, et al.
Published: (2026)
by: Zhu, Jiaying, et al.
Published: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Knowledge-Based Multi-Agent Framework for Automated Software Architecture Design
by: Zhang, Yiran, et al.
Published: (2025)
by: Zhang, Yiran, et al.
Published: (2025)
An Empirical Study of Vulnerability Detection using Federated Learning
by: Zhou, Peiheng, et al.
Published: (2024)
by: Zhou, Peiheng, et al.
Published: (2024)
Promptware Engineering: Software Engineering for Prompt-Enabled Systems
by: Chen, Zhenpeng, et al.
Published: (2025)
by: Chen, Zhenpeng, et al.
Published: (2025)
TIGER: A Generating-Then-Ranking Framework for Practical Python Type Inference
by: Wang, Chong, et al.
Published: (2024)
by: Wang, Chong, et al.
Published: (2024)
An Empirical Study on Noisy Label Learning for Program Understanding
by: Wang, Wenhan, et al.
Published: (2023)
by: Wang, Wenhan, et al.
Published: (2023)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
An Empirical Study of Speculative Decoding on Software Engineering Tasks
by: Li, Yijia, et al.
Published: (2026)
by: Li, Yijia, et al.
Published: (2026)
An Empirical Study on Package-Level Deprecation in Python Ecosystem
by: Zhong, Zhiqing, et al.
Published: (2024)
by: Zhong, Zhiqing, et al.
Published: (2024)
An Interactive Empirical Approach to the Validation of Software Package Specifications
by: Fraser, S. D., et al.
Published: (2024)
by: Fraser, S. D., et al.
Published: (2024)
Similar Items
-
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026) -
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
by: Guo, Wenbo, et al.
Published: (2024) -
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
by: Tang, Wei, et al.
Published: (2024) -
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
by: Zhang, Lyuye, et al.
Published: (2025)