4 papers
TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs
Ting Zhang, Yikun Li, Chengran Yang +15
Software vulnerabilities remain one of the most persistent threats to modern digital infrastructure. While static application security testing (SAST) tools have long served as the…
Taint-Based Code Slicing for LLMs-based Malicious NPM Package Detection
Dang-Khoa Nguyen, Gia-Thang Ho, Quang-Minh Pham +5
Software supply chain attacks on the npm ecosystem have grown increasingly sophisticated, exploiting obfuscation and complex logic to evade detection. Large Language Models (LLMs)…
Towards Classifying Benign And Malicious Packages Using Machine Learning
Thanh-Cong Nguyen, Ngoc-Thanh Nguyen, Van-Giau Ung +1
Recently, the number of malicious open-source packages in package repositories has been increasing dramatically. While major security scanners focus on identifying known Common Vul…
Pack-A-Mal: A Malware Analysis Framework for Open-Source Packages
Duc-Ly Vu, Thanh-Cong Nguyen, Minh-Khanh Vu +2
The increasingly sophisticated environment in which attackers operate makes software security an even greater challenge in open-source projects, where malicious packages are preval…