22 citations · 41 across the 12 of their papers we have counts for
8 papers · 1 filter
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
Biagio Montaruli, Serena Elisa Ponta, Luca Compagna +1
SourceRank is a scoring system made of 18 metrics that assess the popularity and quality of open-source packages. Despite being used in several recent studies, none has thoroughly…
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
Biagio Montaruli, Luca Compagna, Serena Elisa Ponta +1
The rise of supply chain attacks via malicious Python packages demands robust detection solutions. Current approaches, however, overlook two critical challenges: robustness against…
On the Feasibility of Cross-Language Detection of Malicious Packages in npm and PyPI
Piergiorgio Ladisa, Serena Elisa Ponta, Nicola Ronzoni +2
Current software supply chains heavily rely on open-source packages hosted in public repositories. Given the popularity of ecosystems like npm and PyPI, malicious users started to…
The Hitchhiker's Guide to Malicious Third-Party Dependencies
Piergiorgio Ladisa, Merve Sahin, Serena Elisa Ponta +3
The increasing popularity of certain programming languages has spurred the creation of ecosystem-specific package repositories and package managers. Such repositories (e.g., npm, P…
Journey to the Center of Software Supply Chain Attacks
Piergiorgio Ladisa, Serena Elisa Ponta, Antonino Sabetta +2
This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigat…
Towards the Detection of Malicious Java Packages
Piergiorgio Ladisa, Henrik Plate, Matias Martinez +2
Open-source software supply chain attacks aim at infecting downstream users by poisoning open-source packages. The common way of consuming such artifacts is through package reposit…