Fetching the paper…
Reading the bibliography…
Open source code is considered a common practice in modern software development.
Experiences with program static analysis
Hideto Ogasawara, Minoru Aizawa, and Atsushi Yamada · 1998
Earlier work this paper cites.
A survey of malware detection techniques
Nwokedi Idika and Aditya P Mathur · 2007
Earlier work this paper cites.
A look in the mirror: Attacks on package managers
Justin Cappos, Justin Samuel, Scott Baker, and John H Hartman · 2008
Earlier work this paper cites.
Detect related bugs from source code using bug information
Deqing Wang, Mengxiang Lin, Hui Zhang, and Hongping Hu · 2010
Earlier work this paper cites.
Software vulnerability prediction using text analysis techniques
Aram Hovsepyan, Riccardo Scandariato, Wouter Joosen, and James Walden · 2012
Earlier work this paper cites.
https://pvs-studio.com/en/blog/terms/0070/
Dynamic code analysis, 2013 · 2013
Earlier work this paper cites.
Rank based anomaly detection algorithms
Huaming Huang · 2013
Earlier work this paper cites.
Code completion with statistical language models
Veselin Raychev, Martin Vechev, and Eran Yahav · 2014
Earlier work this paper cites.
Tbcnn: A tree-based convolutional neural network for programming language processing
Lili Mou, Ge Li, Zhi Jin, Lu Zhang, and Tao Wang · 2014
Earlier work this paper cites.
https://pvs-studio.com/en/blog/terms/0046/
Static code analysis, 2015 · 2015
Earlier work this paper cites.
Probabilistic model for code with decision trees
Veselin Raychev, Pavol Bielik, and Martin Vechev · 2016
Earlier work this paper cites.
Typosquatting in programming language package managers
Nikolai Philipp Tschacher · 2016
Earlier work this paper cites.
A deep language model for software code
Hoa Khanh Dam, Truyen Tran, and Trang Pham · 2016
Earlier work this paper cites.
How dbscan works and why should we use it?, 2017
Kelvin Salton do Prado · 2017
Earlier work this paper cites.
Detection of malicious javascript code in web pages
Dharmaraj R Patil and JB Patil · 2017
Earlier work this paper cites.
Dbscan revisited, revisited: why and how you should (still) use dbscan
Erich Schubert, Jörg Sander, Martin Ester, Hans Peter Kriegel, and Xiaowei Xu · 2017
Earlier work this paper cites.
Npm attackers sneak a backdoor into node.js deployments through dependencies, 2018
Lucian Constantin · 2018
Earlier work this paper cites.
code2seq: Generating sequences from structured representations of code
Uri Alon, Shaked Brody, Omer Levy, and Eran Yahav · 2018
Earlier work this paper cites.
https://snyk.io/vuln/SNYK-RHEL8-QT5QTTOOLSLIBSDESIGNER-1384820
Double free as an example of a flaw design, 2018 · 2018
Earlier work this paper cites.
An empirical analysis of vulnerabilities in python packages for web applications
Jukka Ruohonen · 2018
Earlier work this paper cites.
Twelve malicious python libraries found and removed from pypi, 2018
Catalin Cimpanu · 2018
Earlier work this paper cites.
You can resurrect any deleted github account name. and this is why we have trust issues, 2018
Thomas Claburn · 2018
Earlier work this paper cites.
Compromised npm package: event-stream, 2018
Thomas Hunter II · 2018
Earlier work this paper cites.
Automated vulnerability detection in source code using deep representation learning
Rebecca Russell, Louis Kim, Lei Hamilton, Tomo Lazovich, Jacob Harer, Onur Ozdemir, Paul Ellingwood, and Marc McConley · 2018
Earlier work this paper cites.
Detecting cyber attacks in the python package index (pypi), 2018
Bertus · 2018
Earlier work this paper cites.
Bert: Pre-training of deep bidirectional transformers for language understanding
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova · 2018
Earlier work this paper cites.
Automatic generation of text descriptive comments for code blocks
Yuding Liang and Kenny Zhu · 2018
Earlier work this paper cites.
Discord token stealer discovered in pypi repository, 2019
Bertus · 2019
Cited alongside, same era.
Codesearchnet challenge: Evaluating the state of semantic code search
Hamel Husain, Ho-Hsiang Wu, Tiferet Gazit, Miltiadis Allamanis, and Marc Brockschmidt · 2019
Cited alongside, same era.
Small world with high risks: A study of security threats in the npm ecosystem
Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel · 2019
Cited alongside, same era.
Malicious python libraries targeting linux servers removed from pypi, 2019
Catalin Cimpanu · 2019
Cited alongside, same era.
Detecting suspicious package updates
Kalil Garrett, Gabriel Ferreira, Limin Jia, Joshua Sunshine, and Christian Kästner · 2019
Cited alongside, same era.
Evading machine learning malware classifiers, 2019
Codecov supply chain attack breakdown, 2021
Mackenzie Jackson · 2021
Later among the works it cites.
2021 state of the software supply chain, 2021
Sonatype · 2021
Later among the works it cites.
https://cri.dev/posts/2021-04-15-monero-mining-attack-github-actions-pull-request/
Beware of monero mining attacks through github actions and malicious pull requests, 2021 · 2021
Later among the works it cites.
Defending against software supply chain attacks, 2021
NIST · 2021
Later among the works it cites.
Next-gen software supply chain attacks up 650% in 2021, 2021
Paul Sawers · 2021
Later among the works it cites.
Newly identified dependency confusion packages target amazon, zillow, and slack; go beyond just bug bounties, 2021
Ax Sharma · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
William Flesman · 2019
Cited alongside, same era.
Scalable source code similarity detection in large code repositories
Firas Alomari and Muhammed Harbi · 2019
Cited alongside, same era.
A systematic review on code clone detection
Qurat Ul Ain, Wasi Haider Butt, Muhammad Waseem Anwar, Farooque Azam, and Bilal Maqbool · 2019
Cited alongside, same era.
Empirical study of python call graph
Li Yu · 2019
Cited alongside, same era.
5 ways to detect outliers that every data scientist should know (python code), 2019
Will Badr · 2019
Cited alongside, same era.
How to cluster in high dimensions, 2019
Oskolkov Nikolay · 2019
Cited alongside, same era.
Backstabber’s knife collection: A review of open source software supply chain attacks
Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier · 2020
Cited alongside, same era.
Software supply chain attacks, 2021
Julie Peterson · 2021
Later among the works it cites.
Supply chain attacks: How to reduce open-source vulnerabilities, 2021
Jennifer Gregory · 2021
Later among the works it cites.
Popular npm project used by millions hijacked in supply-chain attack, 2021
Ax Sharma · 2021
Later among the works it cites.
C++ software security sins, 2021
Mary Kelly · 2021
Later among the works it cites.
It’s unsafe to download some python packages, 2021
Jossef Harush · 2021
Later among the works it cites.
Dependency confusion: How i hacked into apple, microsoft and dozens of other companies, 2021
Alex Birsan · 2021
Later among the works it cites.
https://snyk.io/vuln/SNYK-PYTHON-OPENCVPYTHON-1731340
Opencv-python, division by zero, 2021 · 2021
Later among the works it cites.
A large-scale security-oriented static analysis of python packages in pypi
Jukka Ruohonen, Kalle Hjerppe, and Kalle Rindell · 2021
Later among the works it cites.
Npm package with 3 million weekly downloads had a severe vulnerability, 2021
Ax Shrama · 2021
Later among the works it cites.
Anatomy of a cloud infrastructure attack via a pull request, 2021
Walt Della · 2021
Later among the works it cites.
https://us-cert.cisa.gov/ncas/current-activity/2021/10/22/malware-discovered-popular-npm-package-ua-parser-js
Malware discovered in popular npm package, ua-parser-js, 2021 · 2021
Later among the works it cites.
Breaking down the solarwinds supply chain attack, 2021
Julia Kisielius · 2021
Later among the works it cites.
https://www.sentinelone.com/blog/what-is-a-malware-file-signature-and-how-does-it-work/
What is a malware file signature (and how does it work)?, 2021 · 2021
Later among the works it cites.
Codexglue: A machine learning benchmark dataset for code understanding and generation
Shuai Lu, Daya Guo, Shuo Ren, Junjie Huang, Alexey Svyatkovskiy, Ambrosio Blanco, Colin Clement, Dawn Drain, Daxin Jiang, Duyu Tang, et al · 2021
Later among the works it cites.
Evaluating large language models trained on code
Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde de Oliveira Pinto, Jared Kaplan, Harri Edwards, Yuri Burda, Nicholas Joseph, Greg Brockman, et al · 2021
Later among the works it cites.
Code Search Using Code2Seq
Aishwariya Rao Nagar · 2021
Later among the works it cites.
Python developers are being targeted with malicious packages on pypi, 2022
Andrey Polkovnichenko · 2022
Closest in time.
node-ipc npm package sabotage to protest ukraine invasion, 2022
Pierluigi Paganini · 2022
Closest in time.
https://github.com/PyCQA/bandit
Bandit - a security linter from pycqa, 2022 · 2022
Closest in time.
Ecod: Unsupervised outlier detection using empirical cumulative distribution functions
Zheng Li, Yue Zhao, Xiyang Hu, Nicola Botta, Cezar Ionescu, and George Chen · 2022
Closest in time.