Fetching the paper…
Reading the bibliography…
Package managers have become a vital part of the modern software development process.
“Defcon: Webmin 1.920 Unauthenticated Remote Command Execution”, 2019
Özkan Akkuş · 1920
Earlier work this paper cites.
“An attempt to backdoor the kernel”, 2003
Jonathan Corbet · 2003
Earlier work this paper cites.
“Source Forge Strace Project”, 2004
R McGrath and W Akkerman · 2004
Earlier work this paper cites.
“ClamAV”, 2004
Tomasz Kojm · 2004
Earlier work this paper cites.
“Python web development with Django”
Jeff Forcier, Paul Bissex and Wesley Chun · 2008
Earlier work this paper cites.
“Package management security”
Justin Cappos, Justin Samuel, Scott Baker and John Hartman · 2008
Earlier work this paper cites.
“A look in the mirror: Attacks on package managers”
Justin Cappos, Justin Samuel, Scott Baker and John Hartman · 2008
Earlier work this paper cites.
“DTrace: Dynamic Tracing in Oracle® Solaris, Mac OS X, and FreeBSD.”
Jim Mauro · 2011
Earlier work this paper cites.
“Obfuscation: The hidden malware”
Philip OKane, Sakir Sezer and Kieran McLaughlin · 2011
Earlier work this paper cites.
“web2py Application Development Cookbook”
Pablo Mulone and Mariano Reingart · 2012
Earlier work this paper cites.
“Virustotal-free online virus, malware and url scanner”
Virus Total · 2012
Earlier work this paper cites.
“JavaScript static security analysis made easy with JSPrime”
N Patnaik and S Sahoo · 2013
Earlier work this paper cites.
“Securely adopting mobile technology innovations for your enterprise Using IBM Security Solutions”
Arun Madan, Sridhar Muppidi, Nilesh Patel and Axel Buecker · 2013
Earlier work this paper cites.
“Barecloud: bare-metal analysis-based evasive malware detection”
Dhilung Kirat, Giovanni Vigna and Christopher Kruegel · 2014
Earlier work this paper cites.
“Survey on malware anti-analysis”
Yuxin Gao, Zexin Lu and Yuqing Luo · 2014
Earlier work this paper cites.
“SymJS: automatic symbolic testing of JavaScript web applications”
Guodong Li, Esben Andreasen and Indradeep Ghosh · 2014
Earlier work this paper cites.
“Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps”
Steven Arzt et al · 2014
Earlier work this paper cites.
“Hulk: Eliciting malicious behavior in browser extensions”
Alexandros Kapravelos et al · 2014
Earlier work this paper cites.
“System and application monitoring and troubleshooting with Sysdig”, 2015
Gianluca Borello · 2015
Earlier work this paper cites.
“Malgene: Automatic extraction of malware analysis evasion signature”
Dhilung Kirat and Giovanni Vigna · 2015
Earlier work this paper cites.
“Novel Malware XcodeGhost Modifies Xcode, Infects Apple iOS Apps and Hits App Store”, 2015
Claud Xiao · 2015
Earlier work this paper cites.
“Researchers Solve Juniper Backdoor Mystery; Signs Point to NSA”, 2015
Kim Zetter · 2015
Earlier work this paper cites.
“A Javascript malware analysis tool”, 2015
Sven Taute · 2015
Earlier work this paper cites.
“Typosquatting in programming language package managers”, 2016
Nikolai Tschacher · 2016
Earlier work this paper cites.
“StubDroid: automatic inference of precise data-flow summaries for the android framework”
Steven Arzt and Eric Bodden · 2016
Earlier work this paper cites.
“Evolution of evasive malwares: A survey”
Ashish Jadhav, Deepti Vidyarthi and M Hemavathy · 2016
Earlier work this paper cites.
“Triggerscope: Towards detecting logic bombs in android applications”
Yanick Fratantonio et al · 2016
Earlier work this paper cites.
“Diplomat: Using delegations to protect community repositories”
Trishank Kuppusamy, Santiago Torres-Arias, Vladimir Diaz and Justin Cappos · 2016
Earlier work this paper cites.
“Remote Code Execution on rubygems.org”, 2017
Max Justicz · 2017
Earlier work this paper cites.
“‘crossenv‘ malware on the npm registry”, 2017
NPM Inc · 2017
Earlier work this paper cites.
“Package Phishing”, 2017
fate0 · 2017
Earlier work this paper cites.
“Ten Malicious Libraries Found on PyPI - Python Package Index”, 2017
SK-CSIRT Advisory · 2017
Earlier work this paper cites.
“Why is Malwarebytes blocking Coinhive?”, 2017
Adam Kujawa · 2017
Earlier work this paper cites.
“HUNTING MALICIOUS NPM PACKAGES”, 2017
Jordan Wright · 2017
Cited alongside, same era.
“A survey on automated dynamic malware analysis evasion and counter-evasion: PC, mobile, and web”
Alexei Bulazel and Bülent Yener · 2017
Cited alongside, same era.
“J-force: Forced execution on javascript”
Kyungtae Kim et al · 2017
Cited alongside, same era.
“Mercury: Bandwidth-effective prevention of rollback attacks against community repositories”
Trishank Kuppusamy, Vladimir Diaz and Justin Cappos · 2017
Cited alongside, same era.
“Patch-level verification for bundler”, 2017
Rubysec · 2017
Cited alongside, same era.
“Angr-The Next Generation of Binary Analysis”
Fish Wang and Yan Shoshitaishvili · 2017
Cited alongside, same era.
“Detect potentially malicious PHP files”, 2018
NBS System · 2018
Later among the works it cites.
“QZ: Dynamorio: Dynamic instrumentation tool platform”, 2018
Derek Bruening · 2018
Later among the works it cites.
“RunKit is Node prototyping”, 2018
RunKit · 2018
Later among the works it cites.
“Mystique: Uncovering Information Leakage from Browser Extensions”
Quan Chen and Alexandros Kapravelos · 2018
Later among the works it cites.
“Warning! is rest-client 1.6.13 hijacked?”, 2019
Jussi Koljonen · 2019
Later among the works it cites.
“Small World with High Risks: A Study of Security Threats in the npm Ecosystem”
Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny and Michael Pradel · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
“osquery - Windows, macOS, Linux Monitoring and Intrusion Detection”, 2017
Teddy Reed and Mitchell Grenier · 2017
Cited alongside, same era.
“Flask web development: developing web applications with python”
Miguel Grinberg · 2018
Cited alongside, same era.
“Postmortem for Malicious Packages Published on July 12th, 2018”, 2018
JS Foundation and other contributors · 2018
Cited alongside, same era.
“Cryptocurrency Clipboard Hijacker Discovered in PyPI Repository”, 2018
Bertus · 2018
Cited alongside, same era.
“BreakApp: Automated, Flexible Application Compartmentalization”
Nikos Vasilakis et al · 2018
Cited alongside, same era.
“Synode: Understanding and Automatically Preventing Injection Attacks on Node. js”
Cristian-Alexandru Staicu, Michael Pradel and Benjamin Livshits · 2018
Cited alongside, same era.
“Plot to steal cryptocurrency foiled by the npm security team”, 2019
NPM Inc · 2019
Later among the works it cites.
“The state of open source security report”, 2019
Liran Tal · 2019
Later among the works it cites.
“Use two-factor auth to improve your PyPI account’s security”, 2019
Ernest. Durbin · 2019
Later among the works it cites.
“Practical Approach to Automate the Discovery and Eradication of OpenSource Software Vulnerabilities at Scale”
Aladdin Almubayed · 2019
Later among the works it cites.
“The package destroyer-of-worlds contained malicious code”, 2019
Adam Baldwin · 2019
Later among the works it cites.
“strong_password v0.0.7 rubygem hijacked”, 2019
Tute Costa · 2019
Later among the works it cites.
“Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem”, 2019
Liran Tal · 2019
Later among the works it cites.
“Malicious code in the purescript npm installer”, 2019
Harry Garrood · 2019
Later among the works it cites.
“Security advisories for Npm”, 2019
Npm Inc · 2019
Later among the works it cites.
“All versions of discord.js-user contain malicious code. The package uploads the user’s Discord token to a remote server.”, 2019
NPM Inc · 2019
Later among the works it cites.
“The ast module helps Python applications to process trees of the Python abstract syntax grammar”, 2019
Python Foundation · 2019
Later among the works it cites.
“Parser is a production-ready Ruby parser written in pure Ruby.”, 2019
whitequark · 2019
Later among the works it cites.
“A PHP parser written in PHP”, 2019
Nikita Popov · 2019
Later among the works it cites.
“A static analysis security vulnerability scanner for Ruby on Rails applications”, 2019
Synopsys Inc · 2019
Later among the works it cites.
“Modernize your applications, accelerate innovation Securely build, share and run modern applications anywhere”, 2019
Docker Inc · 2019
Later among the works it cites.
“Airflow is a platform to programmatically author, schedule and monitor workflows.”, 2019
Apache Project · 2019
Later among the works it cites.
“Celery: Distributed Task Queue”, 2019
CeleryProject · 2019
Later among the works it cites.
“ptpb.pw permanent shutdown”, 2019
Zachary Buhman · 2019
Later among the works it cites.
“All versions of fast-requests contain obfuscated malware that uploads Discord user tokens to a remote server”, 2019
NPM Inc · 2019
Later among the works it cites.
“HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs”
Aurore Fass, Michael Backes and Ben Stock · 2019
Later among the works it cites.
“Hack Brief: How to Check Your Computer for Asus Update Malware”, 2019
Lily Newman · 2019
Later among the works it cites.
“in-toto: Providing farm-to-table guarantees for bits and bytes”
Santiago Torres-Arias et al · 2019
Later among the works it cites.
“Detecting suspicious package updates”
Kalil Garrett et al · 2019
Later among the works it cites.
“SourMint: malicious code, ad fraud, and data leak in iOS”, 2020
Alyssa Miller · 2020
Closest in time.
“Bleeping Computer — Wikipedia, The Free Encyclopedia”, 2020
Wikipedia contributors · 2020
Closest in time.
“Measuring and preventing supply chain attacks on package managers”, 2020
Ruian Duan et al · 2020
Closest in time.
“Measuring and preventing supply chain attacks on package managers”, 2020
Ruian Duan et al · 2020
Closest in time.