Large-scale analysis of 200K PyPI packages identifies 1,361 replicated popular packages, 256 replicated vulnerable packages, and 7 new replicated malicious packages, showing replication as a security threat vector.
Large scale study of orphan vulnerabilities in the software supply chain,
2 Pith papers cite this work. Polarity classification is still indexing.
2
Pith papers citing it
fields
cs.SE 2years
2026 2verdicts
UNVERDICTED 2representative citing papers
Empirical evaluation shows popular SBOM tools miss CIMs across languages, so security-grade SBOMs are not achievable under current definitions.
citing papers explorer
-
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Large-scale analysis of 200K PyPI packages identifies 1,361 replicated popular packages, 256 replicated vulnerable packages, and 7 new replicated malicious packages, showing replication as a security threat vector.
-
Poking Around in the Dark: Why a Shared Understanding of Components Matters
Empirical evaluation shows popular SBOM tools miss CIMs across languages, so security-grade SBOMs are not achievable under current definitions.