Pith. sign in

Paper Citation Record · LEDGER

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow

As of 24 August 2026, this Paper Citation Record lists 53 of 53 outbound references and 1 inbound Pith citation observation for arXiv:2606.19063.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.19063 v2

Coverage vector

measured 53 of 53 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-06-26T20:32:00.638453Z

measured 54 of 54 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-02T00:07:41.536427Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

53 of 53 outbound references displayed

  • verified exact4
  • verified fuzzy0
  • unresolved49
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation dced5e08-4df7-485a-b8e5-4ca857e5d9ed · outbound

This paper cites 2026 open source security and risk analysis report.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow 2026 open source security and risk analysis report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:fb4e917ea6f6d8e12ea5ef33815538539654575c8a009bc5fa659db19778d9ef

Observation 4b67ad13-44e1-44dc-8145-447b5379bd5c · outbound

This paper cites Huawei company. pypi mirror of huawei company.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Huawei company. pypi mirror of huawei company

Reference 2

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:c0d1e2302fa29ebc9a0f93820b1edc5ed3ee153fac557c73eaec93d04a0e56e9

Observation 33aedeb0-9a64-4dc1-8743-295198dd9ea3 · outbound

This paper cites Tencent company. pypi mirror of tencent company.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Tencent company. pypi mirror of tencent company

Reference 3

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:c95bce2e689d258210b275494d01fc1a80b10ee86c27c4690c667b049cfc1944

Observation 36e340fd-e826-4acd-ad4a-8072ecdaaf9a · outbound

This paper cites Alibaba company. pypi mirror of alibaba company.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Alibaba company. pypi mirror of alibaba company

Reference 4

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:5b58dab2896f64bae99a70c654b9fdb59171d13e01c4d0ed1a7c6e42aa8b8645

Observation 123177ef-8daf-4a78-9b98-3448596d6d1e · outbound

This paper cites Pypi index.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi index

Reference 5

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:02b012a92522de27aefa219645a144923c572654c1f20ee35eb2d414cc799faf

Observation 0a9c3ce6-48d0-4309-875c-d77d598a8caa · outbound

This paper cites Pypi simple.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi simple

Reference 6

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:5897ce2122cde4ccb00117699c73af52e86520a6c4527f578148355443070da1

Observation 868607dd-7b0d-4a79-b05d-1b4d45067c43 · outbound

This paper cites Beyond typosquatting: an in-depth look at package confusion,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Beyond typosquatting: an in-depth look at package confusion,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:ef42193b2256cba31e89af951bb400e347a5b88888d97bfdadff1ca821b2ef29

Observation 4aaac136-5713-4237-a5d7-453409dd6424 · outbound

This paper cites Continuous intrusion: Characterizing the security of continuous integration services,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Continuous intrusion: Characterizing the security of continuous integration services,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:c1245e3c6d99dd4303e1e7f391a3bda30f9ecbedf077e49010c00128ec364ae0

Observation 7b4056e6-93ad-4a04-bdb9-fa57c7688a65 · outbound

This paper cites Investigating package related security threats in software registries,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Investigating package related security threats in software registries,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:3161ecaa74c5f1ff379dda7d922ad66aa7017fef918afa07a8326e04f9f91520

Observation 43e116ac-6f6d-4b06-9923-19ac07132300 · outbound

This paper cites State of the software supply chain.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow State of the software supply chain

Reference 11

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:5f48ca74fbc3d3a49826c08db0ced7e38fe56a3b047b0a97953489d155724bce

Observation c586b72b-6dd9-4ede-b792-8f0ac2d8a6b5 · outbound

This paper cites ”tianwen.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen

Reference 12

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:7203fda437a9a8ac2532e15cadb4a5eacc364a753c1e9376883547cebdfa4143

Observation 97c4b8ce-7fd4-464d-9445-1d9e0de7c3e0 · outbound

This paper cites ”tianwen.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen

Reference 13

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:a2158920e9c6a48895eac54416ac6f9c8dcc2389118a18bf9d6fe549d69518a0

Observation dc815d29-4e9a-43a5-a44b-461c062f940c · outbound

This paper cites Pypi malicious package analysis: jsonconfig-utils built-in rat backdoor and multi-platform persistence.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi malicious package analysis: jsonconfig-utils built-in rat backdoor and multi-platform persistence

Reference 14

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:f39fda020784e0dc75e84d69c2954ceb01068acfebef39f041935834f2f93a1d

Observation e703542a-11cd-4984-acef-a76fd82dcef3 · outbound

This paper cites ”tianwen.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen

Reference 15

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:5f40d81df9272f73478d4cdb6fe93ddfada6f7c05a8abc98baf1d1ce877bac92

Observation c686d1af-d2b7-4ca5-8336-d563787a3f5e · outbound

This paper cites ”tianwen.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen

Reference 16

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:b5587694ea69456999e8a946342bfc283e6f36fb6d019eb9ef4e80e7d5de9c40

Observation 55e35acc-54bb-47b9-9aa6-13e1f8149917 · outbound

This paper cites Pypi inundated by malicious typosquatting campaign.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi inundated by malicious typosquatting campaign

Reference 17

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:d92050a2262c928cfa9d908fa0d1db8f67a962493670a8167027de1f0a14246b

Observation 623689e4-616f-4210-83fb-00e19d458118 · outbound

This paper cites Guarddog is a cli tool to identify malicious pypi and npm packages.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Guarddog is a cli tool to identify malicious pypi and npm packages

Reference 18

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:b81151dca4749a10cd154c07afacfb7c8e5d947748d1cc8c83b911e8aab6a706

Observation 133f9004-b1fc-4021-9cd3-3a0ad25c9f84 · outbound

This paper cites Oss gadget is a collection of tools that can help analyze open source projects.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Oss gadget is a collection of tools that can help analyze open source projects

Reference 19

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:e059fa0cf62b98bec1518037c8d84cb067f98339af26b22cdd10a67e114ac328

Observation f9872e4b-88d9-44c9-86b5-489f85f96cf9 · outbound

This paper cites Towards measuring supply chain attacks on package managers for interpreted languages,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Towards measuring supply chain attacks on package managers for interpreted languages,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:1b1a5bd8f7680e520f662e294f40546e85b796dd6a4d011ede0cbcb1f77a2bf1

Observation 888c1875-049f-48c7-94c4-91ea5025d37f · outbound

This paper cites an unresolved cited work.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Unresolved cited work

Reference 21

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:4df29ea1c81c551432f96b7729883883ed7d0ec8a12ecf2c742139b83f37a7f3

Observation 2b169709-a1ff-4585-ad77-9d9ac64d8ab9 · outbound

This paper cites Practical automated detection of malicious npm packages,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Practical automated detection of malicious npm packages,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:5a1d7f4a8090f205a11004e49cf331dc73860091a3dac77eb8659bd63457d620

Observation cfbab558-1680-4a89-bdd8-cd993d5b3466 · outbound

This paper cites Xgboost: A scalable tree boosting system,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Xgboost: A scalable tree boosting system,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:4e3d2480971a756e0a4bafe40b6117731d785f4a555d731a1133a0533d31ee6b

Observation da6714b2-026f-4d8d-81f8-787d1d9c84c6 · outbound

This paper cites Lightgbm: A highly efficient gradient boosting decision tree,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Lightgbm: A highly efficient gradient boosting decision tree,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:d0d263dabb9146943d4805918bd0959b8b92f8dd96d9e619076af660b8849b82

Observation 51382bf1-2460-4de9-935e-90a296be9fa2 · outbound

This paper cites {MalGuard}: Towards{Real-Time}, accurate, and actionable detection of malicious packages in{PyPI}ecosystem,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow {MalGuard}: Towards{Real-Time}, accurate, and actionable detection of malicious packages in{PyPI}ecosystem,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:23a829663b44fdda099cb32b845a91e29e0b49d9a24004f2d9858f39522a9a6f

Observation 96a2f856-b0bd-4623-8157-6a238093306b · outbound

This paper cites An empirical study of malicious code in pypi ecosystem,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow An empirical study of malicious code in pypi ecosystem,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:ee845fd14ecb981db3a7a0b724bfbff692350e8f12e4b57c28e90d5155fc4e0e

Observation 0ff8bcbe-a16c-4099-8c02-2d545394d02f · outbound

This paper cites to do this bandit processes each file, builds an ast from it, and runs appropriate plugins against the ast nodes.” 2024, https://github.com/ PyCQA/bandit.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow to do this bandit processes each file, builds an ast from it, and runs appropriate plugins against the ast nodes.” 2024, https://github.com/ PyCQA/bandit

Reference 27

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:85c4edd2b7aa49e0a666cfa08780ac9f5040f918efd00eb2b1a754847baec532

Observation 542008d8-a56a-420e-a8a5-b5300d245303 · outbound

This paper cites Mal- wukong: Towards fast, accurate, and multilingual detection of malicious code poisoning in oss supply chains,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Mal- wukong: Towards fast, accurate, and multilingual detection of malicious code poisoning in oss supply chains,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:edd48099e02fe207e1e15b38e96a9b2ceeca183f460a4c53b03ec00e127393ff

Observation ac77ace1-1be7-4e51-ab8e-f5f8d5f24438 · outbound

This paper cites 1+ 1¿ 2: Inte- grating deep code behaviors with metadata features for malicious pypi package detection,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow 1+ 1¿ 2: Inte- grating deep code behaviors with metadata features for malicious pypi package detection,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:92879951f21ed71a2969e58240d1f5e6f00bf9de74b92eeb1a75a0c9e6c8d0e0

Observation 5ef7838e-5a99-4c14-b710-b388af82fcfd · outbound

This paper cites Killing two birds with one stone: Malicious package detection in npm and pypi using a single model of malicious behavior sequence,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Killing two birds with one stone: Malicious package detection in npm and pypi using a single model of malicious behavior sequence,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:f73b4cabda3a3d540002745f56a6d4a1679dc57eda1fe8960a2062961a69a30b

Observation 6d1a4b3d-54d3-41a7-b1ea-bf6232aae923 · outbound

This paper cites DeepSeek-V3 Technical Report.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow DeepSeek-V3 Technical Report

Reference 31

Resolution
verified exact
local_arxiv, observed 2026-07-04T01:19:20.525091Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:ea413678ce5c3a3c0d89d400953812c34d8142dad0eb30aef80f2e4e82613540

Observation 60ee840f-4c88-4d4d-a7d5-1ea7a5dc7d99 · outbound

This paper cites Kimi K2: Open Agentic Intelligence.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Kimi K2: Open Agentic Intelligence

Reference 32

Resolution
verified exact
local_arxiv, observed 2026-07-04T01:19:20.521364Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:38b9630ef5487207b8f87c1c5d37d86a021eb63f7d8254955f293c1075311df8

Observation 1ccb330b-3c94-4c1a-8a49-2e51057bfcbd · outbound

This paper cites Doubao, an ai independently developed by bytedance.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Doubao, an ai independently developed by bytedance

Reference 33

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:88a20e470a31381146b47059e1b1fa9d3f8ead1b28d7797f3d3ce0d3cfddfe77

Observation 38bb3d7b-a470-47cc-9120-78a333e98f78 · outbound

This paper cites Glm: General language model pretraining with autoregressive blank infilling,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Glm: General language model pretraining with autoregressive blank infilling,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:1883df9f0bbdb1d40be0954e1045cbe6a627c472adc6ced8c49dcb7d0036d423

Observation 77312bb9-5b12-445b-af08-90e3e5e776ca · outbound

This paper cites Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:e357b2431d0dcc7c8467beaf1095a4643ffdd586869e2d337a5a676bec036dfc

Observation 6af96e24-c905-4ebc-997b-91a5077afe10 · outbound

This paper cites How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-08-06T02:01:42.631685Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:2e4435e949ee2f23b7ad57c9b6e75035b2d5e8203394eaa85d2b796c85e97b04

Observation fa00f166-5a3a-430e-a65b-730a2047cba9 · outbound

This paper cites A decision-theoretic generalization of on-line learning and an application to boosting,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow A decision-theoretic generalization of on-line learning and an application to boosting,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:b66962830319b3b51361f89b8ff2c26fe4ef66c5470ba7f29d2b71e17a81e555

Observation ab6dcf3d-a270-4ff7-b2ba-b0841226a5b6 · outbound

This paper cites Random forests,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Random forests,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:788b66272a1d44ca9fd30ac68cf212f2793d1397d9cd8bc9352d65300b9aeb11

Observation 59c8fb04-51e7-4731-93bd-46a563dd2234 · outbound

This paper cites Leveraging large language models to detect npm malicious packages,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Leveraging large language models to detect npm malicious packages,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:a90560f53c0e20e836a385911a36ebfe66e97bbc113b52afa3aeec0449f32f91

Observation ec98771b-8359-4698-af13-16651f304ec3 · outbound

This paper cites Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:c4f5ccbc58f13913ae1d34742b595e49c9a6a4e46aba6d3cf0e027d6757c724b

Observation 3574378b-dd7b-4e99-a88c-b28acbb12481 · outbound

This paper cites {DONAPI}: Malicious{NPM}packages detector using behavior sequence knowledge mapping,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow {DONAPI}: Malicious{NPM}packages detector using behavior sequence knowledge mapping,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:d85c8b6d12cec201784b8f56cb0cf82d5b1ff1238acbe8e10b7fe97ba686b9c4

Observation b89e20b5-c538-4e1a-a149-1200cd014a93 · outbound

This paper cites On the feasibility of cross-language detection of malicious packages in npm and pypi,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the feasibility of cross-language detection of malicious packages in npm and pypi,

Reference 42

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:e567582bc4356a239d0cd4e241708c303129449664db7b1c965d5d6025026fe5

Observation 090c0f02-2134-48e7-a833-d6b340cf66e2 · outbound

This paper cites Exposing the hidden layer: Software repositories in the service of seo manipulation,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Exposing the hidden layer: Software repositories in the service of seo manipulation,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:80d8383666ff632a07052a43997e6c648c36dd6fe68fe188171319cec5133a40

Observation 3386b489-78bc-49ca-8d3f-0d690e9d52ea · outbound

This paper cites Understanding the response to open-source dependency abandonment in the npm ecosystem,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Understanding the response to open-source dependency abandonment in the npm ecosystem,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:28f978d28695354626be78160454a519090f4abf555f76025f9015f02c6db46e

Observation 49e016d3-0e70-48e1-933f-45dc6771e98a · outbound

This paper cites Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of ukraine.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of ukraine

Reference 45

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:7d6f886ab532c0a72bc2d941d15f00a57efc729149bcd7d96a7e4b5f2e3515ba

Observation 7c72bdb1-e5b3-4b78-a754-4c0b7368fe43 · outbound

This paper cites On the security of containers: Threat modeling, attack analysis, and mitigation strategies,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the security of containers: Threat modeling, attack analysis, and mitigation strategies,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:d0cd30a09d5cb18b817252b08507b5a734ac3a63a8552e0cf37831081b175537

Observation 334ebb74-21c5-4cbd-8966-d8845cb4ae7c · outbound

This paper cites What quality aspects influence the adoption of docker images?.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow What quality aspects influence the adoption of docker images?

Reference 47

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:d6671ac4ddf7840b2954463ae8d267388b3b48fb222d4004de1bfb27d25e55e2

Observation dd61b9e2-f047-4e0d-b8d4-6eea3efa31d3 · outbound

This paper cites Shipwright: A human-in-the-loop system for dockerfile repair,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Shipwright: A human-in-the-loop system for dockerfile repair,

Reference 48

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:9cec8b94fd8fd5a0baaded4dfb8ab4f38ce9cbcf774c1e4e61ea810861ad69d4

Observation 78d14157-b630-41b4-8963-4143d58c0523 · outbound

This paper cites Secrets revealed in container images: An internet-wide study on occurrence and impact,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Secrets revealed in container images: An internet-wide study on occurrence and impact,

Reference 49

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:e6ca03227171b1d6c77f1c5fd7515a7fb523f6a96b2a8c31c44aa50f99ed2eac

Observation c8416cc3-5a3f-42ff-8cc3-4d3128d0766a · outbound

This paper cites On the relation between outdated docker containers, severity vulnerabilities, and bugs,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the relation between outdated docker containers, severity vulnerabilities, and bugs,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:aef6814ed7d3e5987a1573ce73e2bf37b52f366b22ed5d26b3a1b1dcbec600c8

Observation 84458491-bcea-4c75-a47d-373a24538ec1 · outbound

This paper cites On the impact of outdated and vulnerable javascript pack- ages in docker images,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the impact of outdated and vulnerable javascript pack- ages in docker images,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:b56e181f79e309925ebd9364d3ed08cf3ce823d1a2a43296a0db379dcec3cf13

Observation bee29766-20f5-4ced-8809-00457a7b1469 · outbound

This paper cites Meta-Maintanance for Dockerfiles: Are We There Yet?.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Meta-Maintanance for Dockerfiles: Are We There Yet?

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-07-04T01:19:20.512510Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:06004bccf2546aff3bf578a6c8a41f0c2cd657df2ad465dc668966d3a6bb65ba

Observation 0f16ab1d-16be-4160-aae8-b281ddc660dc · outbound

This paper cites Exploring the unchartered space of container registry typosquatting,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Exploring the unchartered space of container registry typosquatting,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:1f0239e021714a5d92fb909ba7f0638271edf2230aafe21a38256fb769a85e83

Observation d98b6835-9a7e-427c-b57e-da1478f40609 · outbound

This paper cites Understanding the security risks of docker hub,.

PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Understanding the security risks of docker hub,

Reference 54

Resolution
unresolved
no resolver link, observed 2026-06-26T20:32:00.638453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T20:32:00.638453Z digest=sha256:9744491fcd20eeef5745d2c75dbb74926446c96ab792315acd305663a1dcfdc6

Pith citing papers

Observation 7c750ae6-a7e9-4713-bf62-5b186fcf09ae · inbound

Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents cites this paper.

Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T00:07:41.536427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T00:07:41.536427Z digest=sha256:a113fdc940ad7341b2ebf63583226764b11b6e84b2339342ddcfc69b8fbb1327