What the Fork? Finding Hidden Code Clones in npm
Elizabeth Wyss, Lorenzo De Carli, Drew Davidson
Abstract
This work presents findings and mitigations on an understudied issue, which we term shrinkwrapped clones, that is endemic to the npm software package ecosystem. A shrinkwrapped clone is a package which duplicates, or near-duplicates, the code of another package without any indication or reference to the original package. This phenomenon represents a challenge to the hygiene of package ecosystems, as a clone package may siphon interest from the package being cloned, or create hidden duplicates of vulnerable, insecure code which can fly under the radar of audit processes. Motivated by these considerations, we propose unwrapper, a mechanism to programmatically detect shrinkwrapped clones and match them to their source package. unwrapper uses a package difference metric based on directory tree similarity, augmented with a prefilter which quickly weeds out packages unlikely to be clones of a target. Overall, our prototype can compare a given package within the entire npm ecosystem (1,716,061 packages with 20,190,452 different versions) in 72.85 seconds, and it is thus practical for live deployment. Using our tool, we performed an analysis of a subset of npm packages, which resulted in finding up to 6,292 previously unknown shrinkwrapped clones, of which up to 207 carried vulnerabilities from the original package that had already been fixed in the original package. None of such vulnerabilities were discoverable via the standard npm audit process.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f402badb-860f-4373-83d6-ccc967f79ec5Cited by top-tier papers7
- DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge MappingCheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun et al.USENIX Security 2024 · 38 citations
- Bad Snakes: Understanding and Improving Python Package Index Malware ScanningDuc-Ly Vu, Zachary Newman, John Speed MeyersICSE 2023 · 18 citations
- PyRadar: Towards Automatically Retrieving and Validating Source Code Repository Information for PyPI PackagesKai Gao, Weiwei Xu, Wenhao Yang, Minghui ZhouFSE 2024 · 7 citations
- PTV: Scalable Version Detection of Web Libraries and its Security ApplicationXinyue Liu, Haipeng Cai, Lukasz ZiarekICSE 2026
- Debun: Detecting Bundled JavaScript Libraries on Web using Property-Order GraphsSeojin Kim, Sungmin Park, Jihyeok ParkASE 2025
Builds on4
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- When Coding Style Survives Compilation: De-anonymizing Programmers from Executable BinariesAylin Caliskan, Fabian Yamaguchi, Edwin Dauber, Richard E. Harang et al.NDSS 2018 · 125 citations
- NIL: large-scale detection of large-variance clonesTasuku Nakagawa, Yoshiki Higo, Shinji KusumotoFSE 2021 · 41 citations
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted LanguagesRuian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder et al.NDSS 2021
Related papers
- Understanding and Detecting Peer Dependency Resolving Loop in npm EcosystemXingyu Wang, Mingsen Wang, Wenbo Shen, Rui ChangICSE 2025 · 1 citation
- Flexible and Optimal Dependency Management via Max-SMTDonald Pinckney, Federico Cassano, Arjun Guha, Jonathan Bell et al.ICSE 2023 · 10 citations
- From Noise to Signal: Precisely Identify Affected Packages of Known Vulnerabilities in npm EcosystemYingyuan Pu, Lingyun Ying, Yacong GuNDSS 2026 · 4 citations
- Beyond Typosquatting: An In-depth Look at Package ConfusionShradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson et al.USENIX Security 2023
- SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptMasudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel et al.ICSE 2023 · 20 citations
