Fetching the paper…
Reading the bibliography…
With the growing popularity of modularity in software development comes the rise of package managers and language ecosystems.
Obfuscated malicious javascript detection using classification techniques
Peter Likarish, Eunjin Jung, and Insoon Jo · 2009
Earlier work this paper cites.
Suspicious malicious web site detection with strength analysis of a javascript obfuscation
Byung-Ik Kim, Chae-Tae Im, and Hyun-Chul Jung · 2011
Earlier work this paper cites.
The unfortunate reality of insecure libraries
Williams James and Dabirsiaghi Anand · 2012
Earlier work this paper cites.
Detecting obfuscated javascripts from known and unknown obfuscators using machine learning
Bernhard Tellenbach, Sergio Paganoni, and Marc Rennhard · 2016
Earlier work this paper cites.
Typosquatting in programming language package managers
Nikolai Philipp Tschacher · 2016
Earlier work this paper cites.
Jast: Fully syntactic detection of malicious (obfuscated) javascript
Aurore Fass, Robert P Krawczyk, Michael Backes, and Ben Stock · 2018
Earlier work this paper cites.
Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months
Danny Grander · 2018
Earlier work this paper cites.
Malicious javascript code detection based on hybrid analysis
Xincheng He, Lei Xu, and Chunliu Cha · 2018
Earlier work this paper cites.
strong_password v0.0.7 rubygem hijacked
Tute Costa · 2019
Earlier work this paper cites.
Identification of android malware using refined system calls
K Deepa, Radhamani G, Vinod P, MOHAMMAD SHOJAFAR, Neeraj Kumar, and M Conti · 2019
Earlier work this paper cites.
Jstap: A static pre-filter for malicious javascript detection
Aurore Fass, Michael Backes, and Ben Stock · 2019
Earlier work this paper cites.
Detecting suspicious package updates
Kalil Garrett, Gabriel Ferreira, Limin Jia, Joshua Sunshine, and Christian Kästner · 2019
Earlier work this paper cites.
The hybrid technique for ddos detection with supervised learning algorithms
Soodeh Hosseini and Mehrdad Azizi · 2019
Earlier work this paper cites.
Anything to hide? studying minified and obfuscated code in the web
Philippe Skolka, Cristian-Alexandru Staicu, and Michael Pradel · 2019
Earlier work this paper cites.
Small world with high risks: A study of security threats in the npm ecosystem
Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel · 2019
Earlier work this paper cites.
Intelligent malicious url detection with feature analysis
Yu-Chen Chen, Yi-Wei Ma, and Jiann-Liang Chen · 2020
Earlier work this paper cites.
Malicious npm packages caught installing remote access trojans
Catalin Cimpanu · 2020
Earlier work this paper cites.
Detecting malicious javascript code based on semantic analysis
Yong Fang, Cheng Huang, Yu Su, and Yaoyao Qiu · 2020
Earlier work this paper cites.
Improving malicious urls detection via feature engineering: Linear and nonlinear space transformation methods
Tie Li, Gang Kou, and Yi Peng · 2020
Earlier work this paper cites.
Building auto-encoder intrusion detection system based on random forest feature selection
XuKui Li, Wei Chen, Qianru Zhang, and Lifa Wu · 2020
Earlier work this paper cites.
Supporting the detection of software supply chain attacks through unsupervised signature generation
Marc Ohm, Lukas Kempf, Felix Boes, and Michael Meier · 2020
Earlier work this paper cites.
Towards detection of software supply chain attacks by forensic artifacts
Marc Ohm, Arnold Sykosch, and Michael Meier · 2020
Earlier work this paper cites.
Spellbound: Defending against package typosquatting
Matthew Taylor, Ruturaj K Vaidya, Drew Davidson, Lorenzo De Carli, and Vaibhav Rastogi · 2020
Earlier work this paper cites.
Esg survey report: Modern application development security
Veracode · 2020
Earlier work this paper cites.
An empirical study of usages, updates and risks of third-party libraries in java projects
Ying Wang, Bihuan Chen, Kaifeng Huang, Bowen Shi, Congying Xu, Xin Peng, Yijian Wu, and Yang Liu · 2020
Earlier work this paper cites.
Automated third-party library detection for android applications: Are we there yet?
Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen, Li Li, Haoyu Wang, Yifei Xu, Xiapu Luo, and Yang Liu · 2020
Earlier work this paper cites.
Javascript growing pains: From 0 to 13,000 dependencies
Nikola Đuza · 2020
Earlier work this paper cites.
Dependency confusion: How i hacked into apple, microsoft and dozens of other companies
Birsan Alex · 2021
Cited alongside, same era.
A multi-perspective malware detection approach through behavioral fusion of api call sequence
Eslam Amer, Ivan Zelinka, and Shaker El-Sappagh · 2021
Cited alongside, same era.
Lags in the release, adoption, and propagation of npm vulnerability fixes
Bodin Chinthanet, Raula Gaikovina Kula, Shane McIntosh, Takashi Ishio, Akinori Ihara, and Kenichi Matsumoto · 2021
Cited alongside, same era.
How to use environment variables in npm scripts safely across operating systems
Jimmy Cleveland · 2021
Cited alongside, same era.
Towards measuring supply chain attacks on package managers for interpreted languages
Ruian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder, Brendan Saltaformaggio, and Wenke Lee · 2021
Cited alongside, same era.
Practical automated detection of malicious npm packages
Adriana Sejfia and Max Schäfer · 2022
Later among the works it cites.
Common payloads attackers plant in malicious software packages
Jonathan Sar Shalom · 2022
Later among the works it cites.
Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of ukraine
Liran Tal · 2022
Later among the works it cites.
Towards understanding third-party library dependency in c/c++ ecosystem
Wei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu, Shouguo Yang, Yi Li, Ping Luo, and Yang Liu · 2022
Later among the works it cites.
What the fork? finding hidden code clones in npm
Elizabeth Wyss, Lorenzo De Carli, and Drew Davidson · 2022
Later among the works it cites.
Wolf at the door: Preventing install-time attacks in npm with latch
Elizabeth Wyss, Alexander Wittman, Drew Davidson, and Lorenzo De Carli · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Gabriel Ferreira, Limin Jia, Joshua Sunshine, and Christian Kästner · 2021
Cited alongside, same era.
Leveraging team dynamics to predict open-source software projects’ susceptibility to social engineering attacks
Luiz Giovanini, Daniela Oliveira, Huascar Sanchez, and Deborah Shands · 2021
Cited alongside, same era.
Malicious packages lurking in user-friendly python package index
Genpei Liang, Xiangyu Zhou, Qingyu Wang, Yutong Du, and Cheng Huang · 2021
Cited alongside, same era.
Statically detecting javascript obfuscation and minification techniques in the wild
Marvin Moog, Markus Demmel, Michael Backes, and Aurore Fass · 2021
Cited alongside, same era.
Efficient deep learning models for dga domain detection
Juhong Namgung, Siwoon Son, and Yang-Sae Moon · 2021
Cited alongside, same era.
Detecting third-party library problems with combined program analysis
Grigoris Ntousakis, Sotiris Ioannidis, and Nikos Vasilakis · 2021
Cited alongside, same era.
A comprehensive survey on identification of malware types and malware classification using machine learning techniques
Nagababu Pachhala, S Jothilakshmi, and Bhanu Prakash Battula · 2021
Cited alongside, same era.
Later among the works it cites.
What are weak links in the npm supply chain?
Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Maddila, and Laurie Williams · 2022
Later among the works it cites.
Dozens of malicious npm packages steal user, system data
Ionut Arghire · 2023
Later among the works it cites.
New phishing attack hijacks email thread to inject malicious url
Balaji · 2023
Later among the works it cites.
What is static analysis? static code analysis overview
Richard Bellairs · 2023
Later among the works it cites.
Software supply chain: review of attacks, risk assessment strategies and security controls
Betul Gokkaya, Leonardo Aniello, and Basel Halak · 2023
Later among the works it cites.
Investigating package related security threats in software registries
Yacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu, Huajun Chai, Ruimin Wang, Xing Gao, and Haixin Duan · 2023
Later among the works it cites.
Dependency confusion
Hacktricks · 2023
Later among the works it cites.
https://jscrambler.com/ , 2023
Jscrambler · 2023
Later among the works it cites.
Scaling javascript abstract interpretation to detect and exploit node. js taint-style vulnerability
Mingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo, Jianwei Hou, VN Venkatakrishnan, and Yinzhi Cao · 2023
Later among the works it cites.
On the feasibility of cross-language detection of malicious packages in npm and pypi
Piergiorgio Ladisa, Serena Elisa Ponta, Nicola Ronzoni, Matias Martinez, and Olivier Barais · 2023
Later among the works it cites.
A needle is an outlier in a haystack: Hunting malicious pypi packages with code clustering
Wentao Liang, Xiang Ling, Jingzheng Wu, Tianyue Luo, and Yanjun Wu · 2023
Later among the works it cites.
Review of recent npm-based vulnerabilities
Dotan Nahum · 2023
Later among the works it cites.
Beyond typosquatting: An in-depth look at package confusion
Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, and Lorenzo De Carli · 2023
Later among the works it cites.
https://docs.npmjs.com/cli/v10/commands/npm-audit , 2023
Npm-audit · 2023
Later among the works it cites.
An empirical study on the effects of obfuscation on static machine learning-based malicious javascript detectors
Kunlun Ren, Weizhong Qiang, Yueming Wu, Yi Zhou, Deqing Zou, and Hai Jin · 2023
Later among the works it cites.
Silent spring: Prototype pollution leads to remote code execution in node.js
Mikhail Shcherbakov, Musard Balliu, and Cristian-Alexandru Staicu · 2023
Later among the works it cites.
Phylum discovers sophisticated ongoing attack on npm
Phylum Research Team · 2023
Later among the works it cites.
Taintmini: Detecting flow of sensitive data in mini-programs with static taint analysis
Chao Wang, Ronny Ko, Yue Zhang, Yuqing Yang, and Zhiqiang Lin · 2023
Later among the works it cites.
https://das-lab.github.io/Donapi/ , 2024
Donapi’s hierarchical classification framework · 2024
Closest in time.
The state of software supply chain security (sscs) 2024
ReversingLabs · 2024
Closest in time.