3 papers
cs.CR2025
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
Ben Swierzy, Timo Pohl, Marc Ohm +1
Quantitative metrics derived from software repositories and package ecosystems are widely used to assess the impact, popularity, maintenance, and criticality of free and open sourc…
cs.SE2025
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
Timo Pohl, Pavel Novák, Marc Ohm +1
The disconnect between distributed software artifacts and their supposed source code enables attackers to leverage the build process for inserting malicious functionality. Past res…
cs.CR2023
You Can Run But You Can't Hide: Runtime Protection Against Malicious Package Updates For Node.js
Marc Ohm, Timo Pohl, Felix Boes
Maliciously prepared software packages are an extensively leveraged weapon for software supply chain attacks. The detection of malicious packages is undoubtedly of high priority an…