Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
Fuente:
arXiv
Saved in:
| Main Authors: | Robinson, Michael, Halder, Sajal, Ahmed, Muhammad Ejaz, Ikram, Muhammad, Camtepe, Seyit, Kim, Hyoungshick |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
FuncVul: An Effective Function Level Vulnerability Detection Model using LLM and Code Chunk
by: Halder, Sajal, et al.
Published: (2025)
by: Halder, Sajal, et al.
Published: (2025)
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024)
by: Amjad, Abdul Haddi, et al.
Published: (2024)
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026)
by: Zhang, Lingming, et al.
Published: (2026)
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
by: Pagano, Francesco, et al.
Published: (2026)
by: Pagano, Francesco, et al.
Published: (2026)
AdaDoS: Adaptive DoS Attack via Deep Adversarial Reinforcement Learning in SDN
by: Shao, Wei, et al.
Published: (2025)
by: Shao, Wei, et al.
Published: (2025)
A Study of Vulnerability Repair in JavaScript Programs with Large Language Models
by: Le, Tan Khang, et al.
Published: (2024)
by: Le, Tan Khang, et al.
Published: (2024)
Characterizing Phishing Pages by JavaScript Capabilities
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Prompting the Priorities: A First Look at Evaluating LLMs for Vulnerability Triage and Prioritization
by: Haddad, Osama Al, et al.
Published: (2025)
by: Haddad, Osama Al, et al.
Published: (2025)
An Empirical Study of JavaScript Inclusion Security Issues in Chrome Extensions
by: Guan, Chong
Published: (2025)
by: Guan, Chong
Published: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
by: Cornelissen, Eric, et al.
Published: (2024)
by: Cornelissen, Eric, et al.
Published: (2024)
Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
by: Pereira, Pedro, et al.
Published: (2025)
by: Pereira, Pedro, et al.
Published: (2025)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript Deobfuscation
by: Chen, Guoqiang, et al.
Published: (2025)
by: Chen, Guoqiang, et al.
Published: (2025)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
by: Ali, Mir Masood, et al.
Published: (2024)
by: Ali, Mir Masood, et al.
Published: (2024)
Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
by: Fei, Qingyuan, et al.
Published: (2025)
by: Fei, Qingyuan, et al.
Published: (2025)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
Breaking Obfuscation: Cluster-Aware Graph with LLM-Aided Recovery for Malicious JavaScript Detection
by: Liang, Zhihong, et al.
Published: (2025)
by: Liang, Zhihong, et al.
Published: (2025)
CASCADE: LLM-Powered JavaScript Deobfuscator at Google
by: Jiang, Shan, et al.
Published: (2025)
by: Jiang, Shan, et al.
Published: (2025)
Quantum Key Distribution
by: Kish, Sebastian, et al.
Published: (2025)
by: Kish, Sebastian, et al.
Published: (2025)
The Hidden DNA of LLM-Generated JavaScript: Structural Patterns Enable High-Accuracy Authorship Attribution
by: Tihanyi, Norbert, et al.
Published: (2025)
by: Tihanyi, Norbert, et al.
Published: (2025)
Characterizing JavaScript Security Code Smells
by: Kambhampati, Vikas, et al.
Published: (2024)
by: Kambhampati, Vikas, et al.
Published: (2024)
DyMA-Fuzz: Dynamic Direct Memory Access Abstraction for Re-hosted Monolithic Firmware Fuzzing
by: Farrelly, Guy, et al.
Published: (2026)
by: Farrelly, Guy, et al.
Published: (2026)
MTDSense: AI-Based Fingerprinting of Moving Target Defense Techniques in Software-Defined Networking
by: Moghaddam, Tina, et al.
Published: (2024)
by: Moghaddam, Tina, et al.
Published: (2024)
ST-DPGAN: A Privacy-preserving Framework for Spatiotemporal Data Generation
by: Shao, Wei, et al.
Published: (2024)
by: Shao, Wei, et al.
Published: (2024)
A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy
by: Mohsin, Ahmad, et al.
Published: (2025)
by: Mohsin, Ahmad, et al.
Published: (2025)
Blind-Touch: Homomorphic Encryption-Based Distributed Neural Network Inference for Privacy-Preserving Fingerprint Authentication
by: Choi, Hyunmin, et al.
Published: (2023)
by: Choi, Hyunmin, et al.
Published: (2023)
Attacking Slicing Network via Side-channel Reinforcement Learning Attack
by: Shao, Wei, et al.
Published: (2024)
by: Shao, Wei, et al.
Published: (2024)
Private Synthetic Data Generation in Bounded Memory
by: Holland, Rayne, et al.
Published: (2024)
by: Holland, Rayne, et al.
Published: (2024)
Statement-Level Vulnerability Detection: Learning Vulnerability Patterns Through Information Theory and Contrastive Learning
by: Nguyen, Van, et al.
Published: (2022)
by: Nguyen, Van, et al.
Published: (2022)
EaTVul: ChatGPT-based Evasion Attack Against Software Vulnerability Detection
by: Liu, Shigang, et al.
Published: (2024)
by: Liu, Shigang, et al.
Published: (2024)
Provably Unlearnable Data Examples
by: Wang, Derui, et al.
Published: (2024)
by: Wang, Derui, et al.
Published: (2024)
When the Abyss Looks Back: Unveiling Evolving Dark Patterns in Cookie Consent Banners
by: Singh, Nivedita, et al.
Published: (2026)
by: Singh, Nivedita, et al.
Published: (2026)
Contextualizing Sink Knowledge for Java Vulnerability Discovery
by: Fleischer, Fabian, et al.
Published: (2026)
by: Fleischer, Fabian, et al.
Published: (2026)
CyberAlly: Leveraging LLMs and Knowledge Graphs to Empower Cyber Defenders
by: Kim, Minjune, et al.
Published: (2025)
by: Kim, Minjune, et al.
Published: (2025)
Similar Items
-
FuncVul: An Effective Function Level Vulnerability Detection Model using LLM and Code Chunk
by: Halder, Sajal, et al.
Published: (2025) -
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024) -
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026) -
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
by: Pagano, Francesco, et al.
Published: (2026) -
AdaDoS: Adaptive DoS Attack via Deep Adversarial Reinforcement Learning in SDN
by: Shao, Wei, et al.
Published: (2025)