Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Guo, Wenbo, Chen, Zhongwen, Xu, Zhengzi, Liu, Chengwei, Kang, Ming, Song, Shiwen, Liu, Chengyue, Xu, Yijia, Sun, Weisong, Liu, Yang |
|---|---|
| Format: | Preprint |
| Publié: |
2026
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
par: Guo, Wenbo, et autres
Publié: (2026)
par: Guo, Wenbo, et autres
Publié: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
par: Guo, Wenbo, et autres
Publié: (2026)
par: Guo, Wenbo, et autres
Publié: (2026)
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
par: Guo, Wenbo, et autres
Publié: (2024)
par: Guo, Wenbo, et autres
Publié: (2024)
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
par: Tang, Wei, et autres
Publié: (2024)
par: Tang, Wei, et autres
Publié: (2024)
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
par: Zhang, Lyuye, et autres
Publié: (2025)
par: Zhang, Lyuye, et autres
Publié: (2025)
ModuleGuard:Understanding and Detecting Module Conflicts in Python Ecosystem
par: Zhu, Ruofan, et autres
Publié: (2024)
par: Zhu, Ruofan, et autres
Publié: (2024)
Doctor: Optimizing Container Rebuild Efficiency by Instruction Re-Orchestration
par: Zhu, Zhiling, et autres
Publié: (2025)
par: Zhu, Zhiling, et autres
Publié: (2025)
Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem
par: Tevarut, Napasorn, et autres
Publié: (2025)
par: Tevarut, Napasorn, et autres
Publié: (2025)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
par: Zhang, Junan, et autres
Publié: (2023)
par: Zhang, Junan, et autres
Publié: (2023)
JC-Finder: Detecting Java Clone-based Third-Party Library by Class-level Tree Analysis
par: Zhao, Lida, et autres
Publié: (2025)
par: Zhao, Lida, et autres
Publié: (2025)
Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
par: Hu, Jinchang, et autres
Publié: (2023)
par: Hu, Jinchang, et autres
Publié: (2023)
What About Our Bug? A Study on the Responsiveness of NPM Package Maintainers
par: Saeidi, Mohammadreza, et autres
Publié: (2025)
par: Saeidi, Mohammadreza, et autres
Publié: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
par: Zhou, Xiaoyan, et autres
Publié: (2024)
par: Zhou, Xiaoyan, et autres
Publié: (2024)
Hallucination Detection for LLM-based Text-to-SQL Generation via Two-Stage Metamorphic Testing
par: Yang, Bo, et autres
Publié: (2025)
par: Yang, Bo, et autres
Publié: (2025)
A Machine Learning-Based Approach For Detecting Malicious PyPI Packages
par: Samaana, Haya, et autres
Publié: (2024)
par: Samaana, Haya, et autres
Publié: (2024)
Towards Better Comprehension of Breaking Changes in the NPM Ecosystem
par: Kong, Dezhen, et autres
Publié: (2024)
par: Kong, Dezhen, et autres
Publié: (2024)
UCRBench: Benchmarking LLMs on Use Case Recovery
par: Xiao, Shuyuan, et autres
Publié: (2025)
par: Xiao, Shuyuan, et autres
Publié: (2025)
Scaling Test-Driven Code Generation from Functions to Classes: An Empirical Study
par: Liang, Yunhao, et autres
Publié: (2026)
par: Liang, Yunhao, et autres
Publié: (2026)
Requirements Development and Formalization for Reliable Code Generation: A Multi-Agent Vision
par: Lu, Xu, et autres
Publié: (2025)
par: Lu, Xu, et autres
Publié: (2025)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
par: Ibiyo, Motunrayo, et autres
Publié: (2025)
par: Ibiyo, Motunrayo, et autres
Publié: (2025)
Evolaris: A Roadmap to Self-Evolving Software Intelligence Management
par: Liu, Chengwei, et autres
Publié: (2025)
par: Liu, Chengwei, et autres
Publié: (2025)
GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis
par: Sun, Yuqiang, et autres
Publié: (2023)
par: Sun, Yuqiang, et autres
Publié: (2023)
Enhancing and Reporting Robustness Boundary of Neural Code Models for Intelligent Code Understanding
par: Han, Tingxu, et autres
Publié: (2026)
par: Han, Tingxu, et autres
Publié: (2026)
Enhancing Function Name Prediction using Votes-Based Name Tokenization and Multi-Task Learning
par: Zhang, Xiaoling, et autres
Publié: (2024)
par: Zhang, Xiaoling, et autres
Publié: (2024)
Many Hands Make Light Work: An LLM-based Multi-Agent System for Detecting Malicious PyPI Packages
par: Zeshan, Muhammad Umar, et autres
Publié: (2026)
par: Zeshan, Muhammad Umar, et autres
Publié: (2026)
iReDev: A Knowledge-Driven Multi-Agent Framework for Intelligent Requirements Development
par: Jin, Dongming, et autres
Publié: (2025)
par: Jin, Dongming, et autres
Publié: (2025)
Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
par: Liu, Yi, et autres
Publié: (2023)
par: Liu, Yi, et autres
Publié: (2023)
SkillClone: Multi-Modal Clone Detection and Clone Propagation Analysis in the Agent Skill Ecosystem
par: Zhu, Jiaying, et autres
Publié: (2026)
par: Zhu, Jiaying, et autres
Publié: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
par: Liu, Shuhan, et autres
Publié: (2025)
par: Liu, Shuhan, et autres
Publié: (2025)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
par: Toda, Takaaki, et autres
Publié: (2026)
par: Toda, Takaaki, et autres
Publié: (2026)
Knowledge-Based Multi-Agent Framework for Automated Software Architecture Design
par: Zhang, Yiran, et autres
Publié: (2025)
par: Zhang, Yiran, et autres
Publié: (2025)
An Empirical Study of Vulnerability Detection using Federated Learning
par: Zhou, Peiheng, et autres
Publié: (2024)
par: Zhou, Peiheng, et autres
Publié: (2024)
Promptware Engineering: Software Engineering for Prompt-Enabled Systems
par: Chen, Zhenpeng, et autres
Publié: (2025)
par: Chen, Zhenpeng, et autres
Publié: (2025)
TIGER: A Generating-Then-Ranking Framework for Practical Python Type Inference
par: Wang, Chong, et autres
Publié: (2024)
par: Wang, Chong, et autres
Publié: (2024)
An Empirical Study on Noisy Label Learning for Program Understanding
par: Wang, Wenhan, et autres
Publié: (2023)
par: Wang, Wenhan, et autres
Publié: (2023)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
par: Ryan, Ahmed, et autres
Publié: (2026)
par: Ryan, Ahmed, et autres
Publié: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
par: Mehedi, Sk Tanzir, et autres
Publié: (2025)
par: Mehedi, Sk Tanzir, et autres
Publié: (2025)
An Empirical Study of Speculative Decoding on Software Engineering Tasks
par: Li, Yijia, et autres
Publié: (2026)
par: Li, Yijia, et autres
Publié: (2026)
An Empirical Study on Package-Level Deprecation in Python Ecosystem
par: Zhong, Zhiqing, et autres
Publié: (2024)
par: Zhong, Zhiqing, et autres
Publié: (2024)
An Interactive Empirical Approach to the Validation of Software Package Specifications
par: Fraser, S. D., et autres
Publié: (2024)
par: Fraser, S. D., et autres
Publié: (2024)
Documents similaires
-
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
par: Guo, Wenbo, et autres
Publié: (2026) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
par: Guo, Wenbo, et autres
Publié: (2026) -
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
par: Guo, Wenbo, et autres
Publié: (2024) -
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
par: Tang, Wei, et autres
Publié: (2024) -
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
par: Zhang, Lyuye, et autres
Publié: (2025)