Fetching the paper…
Reading the bibliography…
PyPI provides a convenient and accessible package management platform to developers, enabling them to quickly implement specific functions and improve work efficiency.
S. Samtani, K. Chinn, C. Larson, and H. Chen, “Azsecure hacker assets portal: Cyber threat intelligence and malware analysis,” in 2016 IEEE conference on intelligence and security informatics (ISI)
2016
Earlier work this paper cites.
F. Fischer, K. Böttinger, H. Xiao, C. Stransky, Y. Acar, M. Backes, and S. Fahl, “Stack overflow considered harmful? the impact of copy&paste on android application security,” in 2017 IEEE Symposium on Security and Privacy (SP)
2017
Earlier work this paper cites.
L. Li, D. Li, T. F. Bissyandé, J. Klein, Y. Le Traon, D. Lo, and L. Cavallaro, “Understanding android app piggybacking: A systematic study of malicious code grafting,” IEEE Transactions on Information Forensics and Security
2017
Earlier work this paper cites.
M. Valiev, B. Vasilescu, and J. Herbsleb, “Ecosystem-level determinants of sustained activity in open-source projects: A case study of the pypi ecosystem,” in Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
2018
Earlier work this paper cites.
M. Shahzad, M. Z. Shafiq, and A. X. Liu, “Large scale characterization of software vulnerability life cycles,” IEEE Transactions on Dependable and Secure Computing
2019
Earlier work this paper cites.
M. Ohm, H. Plate, A. Sykosch, and M. Meier, “Backstabber’s knife collection: A review of open source software supply chain attacks,” in International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment
2020
Earlier work this paper cites.
M. O. F. Rokon, R. Islam, A. Darki, E. E. Papalexakis, and M. Faloutsos, “Sourcefinder: Finding malware source-code from publicly available repositories in github.,” in RAID
2020
Earlier work this paper cites.
2020
Earlier work this paper cites.
Y. Zhang, Y. Fan, S. Hou, Y. Ye, X. Xiao, P. Li, C. Shi, L. Zhao, and S. Xu, “Cyber-guided deep neural network for malicious repository detection in github,” in 2020 IEEE International Conference on Knowledge Graph (ICKG)
2020
Earlier work this paper cites.
2021
Earlier work this paper cites.
B. Kaplan and J. Qian, “A survey on common threats in npm and pypi registries,” in Deployable Machine Learning for Security Defense: Second International Workshop, MLHat 2021, Virtual Event, August 15, 2021, Proceedings 2
2021
Earlier work this paper cites.
M. J. H. Faruk, H. Shahriar, M. Valero, F. L. Barsha, S. Sobhan, M. A. Khan, M. Whitman, A. Cuzzocrea, D. Lo, A. Rahman, et al
2021
Earlier work this paper cites.
L. Liu, L. Wei, W. Zhang, M. Wen, Y. Liu, and S.-C. Cheung, “Characterizing transaction-reverting statements in ethereum smart contracts,” in 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE)
2021
Earlier work this paper cites.
D. Gonzalez, T. Zimmermann, P. Godefroid, and M. Schäfer, “Anomalicious: Automated detection of anomalous and potentially malicious commits on github,” in 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP)
2021
Earlier work this paper cites.
Y. Fang, M. Xie, and C. Huang, “Pbdt: Python backdoor detection model based on combined features,” Security and Communication Networks
2021
Cited alongside, same era.
G. Liang, X. Zhou, Q. Wang, Y. Du, and C. Huang, “Malicious packages lurking in user-friendly python package index,” in 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
2021
Cited alongside, same era.
D.-L. Vu, F. Massacci, I. Pashchenko, H. Plate, and A. Sabetta, “Lastpymile: identifying the discrepancy between sources and packages,” in Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
2021
Cited alongside, same era.
https://pypi.org/ [Accessed December 20, 2022]
“Python package index.” · 2022
Cited alongside, same era.
https://mirrors.sustech.edu.cn/pypi/simple/ [Accessed December 20, 2022]
“Pypi mirror of southern university of science and technology.” · 2022
Later among the works it cites.
https://packagemanager.rstudio.com/pypi/latest/simple/ [Accessed December 20, 2022]
“Pypi mirror of rstudio.” · 2022
Later among the works it cites.
http://mirror.kakao.com/pypi/simple/ [Accessed December 20, 2022]
“Pypi mirror of kakao.” · 2022
Later among the works it cites.
https://file.unpad.ac.id/pypi/web/ [Accessed December 20, 2022]
“Pypi mirror of universitas padjadjaran.” · 2022
Later among the works it cites.
E. Wyss, A. Wittman, D. Davidson, and L. De Carli, “Wolf at the door: Preventing install-time attacks in npm with latch,” in Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
P. Ladisa, H. Plate, M. Martinez, and O. Barais, “Sok: Taxonomy of attacks on open-source software supply chains,” in 2023 IEEE Symposium on Security and Privacy (SP)
2022
Cited alongside, same era.
https://security.snyk.io/ [Accessed December 14, 2022]
“Open source vulnerability database.” · 2022
Cited alongside, same era.
https://pypi.tuna.tsinghua.edu.cn/simple/ [Accessed December 20, 2022]
“Pypi mirror of tsinghua university.” · 2022
Cited alongside, same era.
https://mirrors.cloud.tencent.com/pypi/simple [Accessed December 20, 2022]
“Pypi mirror of tencent company.” · 2022
Cited alongside, same era.
https://mirrors.aliyun.com/pypi/simple/ [Accessed December 20, 2022]
“Pypi mirror of alibaba company.” · 2022
Cited alongside, same era.
http://pypi.doubanio.com/simple/ [Accessed December 20, 2022]
“Pypi mirror of douban company.” · 2022
Cited alongside, same era.
https://www.virustotal.com/gui/home/upload/ [Accessed December 20, 2022]
“Analyse suspicious files, domains, ips and urls to detect malware and other breaches, automatically share them with the security community..” · 2022
Cited alongside, same era.
https://mirrors.huaweicloud.com/repository/pypi/simple/ [Accessed December 20, 2022]
“Pypi mirror of huawei company.” · 2022
Cited alongside, same era.
A. Cao and B. Dolan-Gavitt, “What the fork? finding and analyzing malware in github forks,” in Proc. of NDSS
2022
Later among the works it cites.
A. Zhou, T. Huang, C. Huang, D. Li, and C. Song, “Pycomm: Malicious commands detection model for python scripts,” Journal of Intelligent & Fuzzy Systems
2022
Later among the works it cites.
Y. Gu, L. Ying, Y. Pu, X. Hu, H. Chai, R. Wang, X. Gao, and H. Duan, “Investigating package related security threats in software registries,” in 2023 IEEE Symposium on Security and Privacy (SP)
2022
Later among the works it cites.
https://www.bleepingcomputer.com/news/security/malicious-pypi-package-opens-backdoors-on-windows-linux-and-macs/ [Accessed January 14, 2023]
“Malicious pypi package opens backdoors on windows, linux, and macs.” · 2023
Closest in time.
https://www.bleepingcomputer.com/news/security/dozens-of-pypi-packages-caught-dropping-w4sp-info-stealing-malware/ [Accessed January 14, 2023]
“Dozens of pypi packages caught dropping ’w4sp’ info-stealing malware.” · 2023
Closest in time.
https://twitter.com/ax_sharma/status/1488937021750005762/ [Accessed January 14, 2023]
“New: Pypi packages ‘xss’ and ‘easyfuncsys’ steal roblox session cookies and discord tokens, and drop suspicious exes..” · 2023
Closest in time.
M. Alfadel, D. E. Costa, and E. Shihab, “Empirical analysis of security vulnerabilities in python packages,” Empirical Software Engineering
2023
Closest in time.
https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/init-access_user-driven-attack-packages.htm/ [Accessed January 23, 2023]
“User-driven attack packages.” · 2023
Closest in time.
https://www.sonatype.com/ [Accessed January 30, 2023]
“Sonatype: Software supply chain security - devsecops.” · 2023
Closest in time.