SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and Matching
Abstract
Open source software (OSS) supply chains have been attractive targets for attacks. One of the significant, popular attacks is realized by malicious packages on package registries. NPM, as the largest package registry, has been recently flooded with malicious packages. In response to this severe security risk, many detection tools have been proposed. However, these tools do not model malicious behavior in a holistic way; only consider a predefined set of sensitive APIs; and require huge manual confirmation effort due to high false positives and binary detection results. Thus, their practical usefulness is hindered.
BibTeX
@inproceedings{Huang-al:ASE24,
author = {Yiheng Huang and
Ruisi Wang and
Wen Zheng and
Zhuotong Zhou and
Susheng Wu and
Shulin Ke and
Bihuan Chen and
Shan Gao and
Xin Peng},
title = {{SpiderScan:} Practical Detection of Malicious {NPM} Packages Based on {Graph-Based} Behavior Modeling and Matching},
booktitle = {ASE},
pages = {1146--1158},
publisher = {{ACM}},
year = {2024},
}