Fetching the paper…
Reading the bibliography…
Package managers for software repositories based on a single programming language are very common.
Senate Report 106-140 - THE ANTICYBERSQUATTING CONSUMER PROTECTION ACT, August 1999
1999
Earlier work this paper cites.
The base-rate fallacy and its implications for the difficulty of intrusion detection
Stefan Axelsson · 1999
Earlier work this paper cites.
Cutting through the confusion: A measurement study of homograph attacks
Tobias Holgers, David E. Watson, and Steven D. Gribble · 2006
Earlier work this paper cites.
Strider typo-patrol: Discovery and analysis of systematic typo-squatting
Yi-Min Wang, Doug Beck, Jeffrey Wang, Chad Verbowski, and Brad Daniels · 2006
Earlier work this paper cites.
A look in the mirror: attacks on package managers
Justin Cappos, Justin Samuel, Scott Baker, and John H. Hartman · 2008
Earlier work this paper cites.
The security cost of cheap user interaction
Rainer Böhme and Jens Grossklags · 2011
Earlier work this paper cites.
Mast: Triage for market-scale mobile malware analysis
Saurabh Chakradeo, Bradley Reaves, Patrick Traynor, and William Enck · 2013
Earlier work this paper cites.
The evolution of the r software ecosystem
Daniel M German, Bram Adams, and Ahmed E Hassan · 2013
Earlier work this paper cites.
The maven repository dataset of metrics, changes, and dependencies
Steven Raemaekers, Arie van Deursen, and Joost Visser · 2013
Earlier work this paper cites.
Dependencies: No Software is an Island
Jørgen Tellnes · 2013
Earlier work this paper cites.
The npm blog - numeric precision matters: how npm download counts work, July 2014
2014
Earlier work this paper cites.
Droidkin: Lightweight detection of android apps similarity
Hugo Gonzalez, Natalia Stakhanova, and Ali A. Ghorbani · 2014
Earlier work this paper cites.
Visualizing the Evolution of Systems and Their Library Dependencies
R. G. Kula, C. D. Roover, D. German, T. Ishio, and K. Inoue · 2014
Earlier work this paper cites.
A measurement study of google play
Nicolas Viennot, Edward Garcia, and Jason Nieh · 2014
Earlier work this paper cites.
Using Attack Surface Entry Points and Reachability Analysis to Assess the Risk of Software Vulnerability Exploitability
A. A. Younis, Y. K. Malaiya, and I. Ray · 2014
Earlier work this paper cites.
npm-scope | npm documentation, August 2015
2015
Cited alongside, same era.
Pep 503 – simple repository api, September 2015
2015
Cited alongside, same era.
Tracking known security vulnerabilities in proprietary software systems
Mircea Cadariu, Eric Bouwers, Joost Visser, and Arie van Deursen · 2015
Cited alongside, same era.
Andarwin: Scalable detection of android application clones based on semantics
Jonathan Crussell, Clint Gibler, and Hao Chen · 2015
Cited alongside, same era.
In Dependencies We Trust: How vulnerable are dependencies in software modules?
Joseph Hejderup · 2015
Cited alongside, same era.
Impact assessment for vulnerabilities in open-source software libraries
H. Plate, S. E. Ponta, and A. Sabetta · 2015
Cited alongside, same era.
Email typosquatting
Janos Szurdi and Nicolas Christin · 2017
Later among the works it cites.
Pypi user - wbengtson, January 2018
2018
Later among the works it cites.
The spyware used in intimate partner violence
Rahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, and Thomas Ristenpart · 2018
Later among the works it cites.
A large scale investigation of obfuscation use in google play
Dominik Wermke, Nicolas Huaman, Yasemin Acar, Bradley Reaves, Patrick Traynor, and Sascha Fahl · 2018
Later among the works it cites.
Malicious package report: browserift - snyk.io, July 2019
2019
Later among the works it cites.
Malicious package report: comander - snyk.io, October 2019
2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
The Landscape of Domain Name Typosquatting: Techniques and Countermeasures
Jeffrey Spaulding, Shambhu Upadhyaya, and Aziz Mohaisen · 2016
Cited alongside, same era.
Typosquatting in Programming Language Package Managers
Nikolai Philipp Tschacher · 2016
Cited alongside, same era.
A look at the dynamics of the javascript package ecosystem
Erik Wittern, Philippe Suter, and Shriram Rajagopalan · 2016
Cited alongside, same era.
New package moniker rules, December 2017
2017
Cited alongside, same era.
The npm blog - ’crossenv’ malware on the npm registry, August 2017
2017
Cited alongside, same era.
pypi-parker, October 2017
2017
Cited alongside, same era.
Malicious package report: destroyer-of-worlds - snyk.io, May 2019
2019
Later among the works it cites.
Malicious package report: device-mqtt - snyk.io, August 2019
2019
Later among the works it cites.
npm security advisory: babel-laoder, November 2019
2019
Later among the works it cites.
npm security advisory: sj-tw-sec, November 2019
2019
Later among the works it cites.
Prototype pollution in lodash | snyk, July 2019
2019
Later among the works it cites.
An empirical analysis of the python package index (pypi)
Ethan Bommarito and Michael Bommarito · 2019
Later among the works it cites.
HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs
Aurore Fass, Michael Backes, and Ben Stock · 2019
Later among the works it cites.
Small World with High Risks: A Study of Security Threats in the npm Ecosystem
Markus Zimmermann, Cristian-Alexandru Staicu, and Michael Pradel · 2019
Later among the works it cites.