kirancodes.me
To Proof Maintenance & Beyond!

SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and Matching

Yiheng Huang, Ruisi Wang, Wen Zheng, Zhuotong Zhou, Susheng Wu, Shulin Ke, Bihuan Chen, Shan Gao, Xin Peng

Abstract

Open source software (OSS) supply chains have been attractive targets for attacks. One of the significant, popular attacks is realized by malicious packages on package registries. NPM, as the largest package registry, has been recently flooded with malicious packages. In response to this severe security risk, many detection tools have been proposed. However, these tools do not model malicious behavior in a holistic way; only consider a predefined set of sensitive APIs; and require huge manual confirmation effort due to high false positives and binary detection results. Thus, their practical usefulness is hindered.

BibTeX
@inproceedings{Huang-al:ASE24,
  author    = {Yiheng Huang and
               Ruisi Wang and
               Wen Zheng and
               Zhuotong Zhou and
               Susheng Wu and
               Shulin Ke and
               Bihuan Chen and
               Shan Gao and
               Xin Peng},
  title     = {{SpiderScan:} Practical Detection of Malicious {NPM} Packages Based on {Graph-Based} Behavior Modeling and Matching},
  booktitle = {ASE},
  pages     = {1146--1158},
  publisher = {{ACM}},
  year      = {2024},
}

Related papers