2 papers
cs.SE2026
How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study
Wenbo Guo, Zhongwen Chen, Zhengzi Xu +7
The NPM ecosystem faces escalating threats from malicious packages that exploit its open publication model. While numerous detection tools have been proposed, they are evaluated on…
cs.SE2025
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
Lyuye Zhang, Chengwei Liu, Jiahui Wu +5
The prevalent use of third-party libraries (TPLs) in modern software development introduces significant security and compliance risks, necessitating the implementation of Software…