Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-26T20:32:00.638453Z
Paper Citation Record · LEDGER
As of 24 August 2026, this Paper Citation Record lists 53 of 53 outbound references and 1 inbound Pith citation observation for arXiv:2606.19063.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-26T20:32:00.638453Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-02T00:07:41.536427Z
A source-named dated measurement, never combined with another source.
Source: cited_works
53 of 53 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation dced5e08-4df7-485a-b8e5-4ca857e5d9ed · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow 2026 open source security and risk analysis report
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4b67ad13-44e1-44dc-8145-447b5379bd5c · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Huawei company. pypi mirror of huawei company
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 33aedeb0-9a64-4dc1-8743-295198dd9ea3 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Tencent company. pypi mirror of tencent company
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 36e340fd-e826-4acd-ad4a-8072ecdaaf9a · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Alibaba company. pypi mirror of alibaba company
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 123177ef-8daf-4a78-9b98-3448596d6d1e · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi index
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0a9c3ce6-48d0-4309-875c-d77d598a8caa · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi simple
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 868607dd-7b0d-4a79-b05d-1b4d45067c43 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Beyond typosquatting: an in-depth look at package confusion,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4aaac136-5713-4237-a5d7-453409dd6424 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Continuous intrusion: Characterizing the security of continuous integration services,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7b4056e6-93ad-4a04-bdb9-fa57c7688a65 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Investigating package related security threats in software registries,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 43e116ac-6f6d-4b06-9923-19ac07132300 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow State of the software supply chain
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c586b72b-6dd9-4ede-b792-8f0ac2d8a6b5 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 97c4b8ce-7fd4-464d-9445-1d9e0de7c3e0 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc815d29-4e9a-43a5-a44b-461c062f940c · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi malicious package analysis: jsonconfig-utils built-in rat backdoor and multi-platform persistence
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e703542a-11cd-4984-acef-a76fd82dcef3 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c686d1af-d2b7-4ca5-8336-d563787a3f5e · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow ”tianwen
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 55e35acc-54bb-47b9-9aa6-13e1f8149917 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Pypi inundated by malicious typosquatting campaign
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 623689e4-616f-4210-83fb-00e19d458118 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Guarddog is a cli tool to identify malicious pypi and npm packages
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 133f9004-b1fc-4021-9cd3-3a0ad25c9f84 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Oss gadget is a collection of tools that can help analyze open source projects
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f9872e4b-88d9-44c9-86b5-489f85f96cf9 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Towards measuring supply chain attacks on package managers for interpreted languages,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 888c1875-049f-48c7-94c4-91ea5025d37f · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Unresolved cited work
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2b169709-a1ff-4585-ad77-9d9ac64d8ab9 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Practical automated detection of malicious npm packages,
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cfbab558-1680-4a89-bdd8-cd993d5b3466 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Xgboost: A scalable tree boosting system,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation da6714b2-026f-4d8d-81f8-787d1d9c84c6 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Lightgbm: A highly efficient gradient boosting decision tree,
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 51382bf1-2460-4de9-935e-90a296be9fa2 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow {MalGuard}: Towards{Real-Time}, accurate, and actionable detection of malicious packages in{PyPI}ecosystem,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 96a2f856-b0bd-4623-8157-6a238093306b · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow An empirical study of malicious code in pypi ecosystem,
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ff8bcbe-a16c-4099-8c02-2d545394d02f · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow to do this bandit processes each file, builds an ast from it, and runs appropriate plugins against the ast nodes.” 2024, https://github.com/ PyCQA/bandit
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 542008d8-a56a-420e-a8a5-b5300d245303 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Mal- wukong: Towards fast, accurate, and multilingual detection of malicious code poisoning in oss supply chains,
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ac77ace1-1be7-4e51-ab8e-f5f8d5f24438 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow 1+ 1¿ 2: Inte- grating deep code behaviors with metadata features for malicious pypi package detection,
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5ef7838e-5a99-4c14-b710-b388af82fcfd · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Killing two birds with one stone: Malicious package detection in npm and pypi using a single model of malicious behavior sequence,
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6d1a4b3d-54d3-41a7-b1ea-bf6232aae923 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow DeepSeek-V3 Technical Report
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 60ee840f-4c88-4d4d-a7d5-1ea7a5dc7d99 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Kimi K2: Open Agentic Intelligence
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 1ccb330b-3c94-4c1a-8a49-2e51057bfcbd · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Doubao, an ai independently developed by bytedance
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 38bb3d7b-a470-47cc-9120-78a333e98f78 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Glm: General language model pretraining with autoregressive blank infilling,
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 77312bb9-5b12-445b-af08-90e3e5e776ca · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6af96e24-c905-4ebc-997b-91a5077afe10 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation fa00f166-5a3a-430e-a65b-730a2047cba9 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow A decision-theoretic generalization of on-line learning and an application to boosting,
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ab6dcf3d-a270-4ff7-b2ba-b0841226a5b6 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Random forests,
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 59c8fb04-51e7-4731-93bd-46a563dd2234 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Leveraging large language models to detect npm malicious packages,
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ec98771b-8359-4698-af13-16651f304ec3 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching,
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3574378b-dd7b-4e99-a88c-b28acbb12481 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow {DONAPI}: Malicious{NPM}packages detector using behavior sequence knowledge mapping,
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b89e20b5-c538-4e1a-a149-1200cd014a93 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the feasibility of cross-language detection of malicious packages in npm and pypi,
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 090c0f02-2134-48e7-a833-d6b340cf66e2 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Exposing the hidden layer: Software repositories in the service of seo manipulation,
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3386b489-78bc-49ca-8d3f-0d690e9d52ea · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Understanding the response to open-source dependency abandonment in the npm ecosystem,
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 49e016d3-0e70-48e1-933f-45dc6771e98a · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of ukraine
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7c72bdb1-e5b3-4b78-a754-4c0b7368fe43 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the security of containers: Threat modeling, attack analysis, and mitigation strategies,
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 334ebb74-21c5-4cbd-8966-d8845cb4ae7c · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow What quality aspects influence the adoption of docker images?
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dd61b9e2-f047-4e0d-b8d4-6eea3efa31d3 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Shipwright: A human-in-the-loop system for dockerfile repair,
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 78d14157-b630-41b4-8963-4143d58c0523 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Secrets revealed in container images: An internet-wide study on occurrence and impact,
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c8416cc3-5a3f-42ff-8cc3-4d3128d0766a · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the relation between outdated docker containers, severity vulnerabilities, and bugs,
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 84458491-bcea-4c75-a47d-373a24538ec1 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow On the impact of outdated and vulnerable javascript pack- ages in docker images,
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bee29766-20f5-4ced-8809-00457a7b1469 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Meta-Maintanance for Dockerfiles: Are We There Yet?
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 0f16ab1d-16be-4160-aae8-b281ddc660dc · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Exploring the unchartered space of container registry typosquatting,
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d98b6835-9a7e-427c-b57e-da1478f40609 · outbound
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow Understanding the security risks of docker hub,
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7c750ae6-a7e9-4713-bf62-5b186fcf09ae · inbound
Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.