activity
20122026
most citedOn the Feasibility of Cross-Language Detection of Malicious Packages in npm and PyPI

22 citations · 41 across the 12 of their papers we have counts for

collaborators
Showing cs.CRShow all

8 papers · 1 filter

cs.CR2025

SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem

Biagio Montaruli, Serena Elisa Ponta, Luca Compagna +1

SourceRank is a scoring system made of 18 metrics that assess the popularity and quality of open-source packages. Despite being used in several recent studies, none has thoroughly…

cs.CR2025

One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises

Biagio Montaruli, Luca Compagna, Serena Elisa Ponta +1

The rise of supply chain attacks via malicious Python packages demands robust detection solutions. Current approaches, however, overlook two critical challenges: robustness against…

cs.CR2023★ 22 cited

On the Feasibility of Cross-Language Detection of Malicious Packages in npm and PyPI

Piergiorgio Ladisa, Serena Elisa Ponta, Nicola Ronzoni +2

Current software supply chains heavily rely on open-source packages hosted in public repositories. Given the popularity of ecosystems like npm and PyPI, malicious users started to…

cs.CR2023★ 12 cited

The Hitchhiker's Guide to Malicious Third-Party Dependencies

Piergiorgio Ladisa, Merve Sahin, Serena Elisa Ponta +3

The increasing popularity of certain programming languages has spurred the creation of ecosystem-specific package repositories and package managers. Such repositories (e.g., npm, P…

cs.CR2023

Journey to the Center of Software Supply Chain Attacks

Piergiorgio Ladisa, Serena Elisa Ponta, Antonino Sabetta +2

This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigat…

cs.CR2022

Towards the Detection of Malicious Java Packages

Piergiorgio Ladisa, Henrik Plate, Matias Martinez +2

Open-source software supply chain attacks aim at infecting downstream users by poisoning open-source packages. The common way of consuming such artifacts is through package reposit…