4 papers
Taint-Based Code Slicing for LLMs-based Malicious NPM Package Detection
Dang-Khoa Nguyen, Gia-Thang Ho, Quang-Minh Pham +5
Software supply chain attacks on the npm ecosystem have grown increasingly sophisticated, exploiting obfuscation and complex logic to evade detection. Large Language Models (LLMs)…
Pack-A-Mal: A Malware Analysis Framework for Open-Source Packages
Duc-Ly Vu, Thanh-Cong Nguyen, Minh-Khanh Vu +2
The increasingly sophisticated environment in which attackers operate makes software security an even greater challenge in open-source projects, where malicious packages are preval…
Towards Classifying Benign And Malicious Packages Using Machine Learning
Thanh-Cong Nguyen, Ngoc-Thanh Nguyen, Van-Giau Ung +1
Recently, the number of malicious open-source packages in package repositories has been increasing dramatically. While major security scanners focus on identifying known Common Vul…
A Study of Malware Prevention in Linux Distributions
Duc-Ly Vu, Trevor Dunlap, Karla Obermeier-Velazquez +4
Malicious attacks on open-source software packages are a growing concern. The discovery of the XZ Utils backdoor intensified these concerns because of the potential widespread impa…