PyFEX: Uncovering Evasive Python-based Threats via Resilient and Exhaustive Path Exploration
Meng Wang, Yue Ma, Majid Garoosi, Wenting Fan, Liwei Guo, Jiangqiang Wang, Ali Abbasi
摘要
The rapid expansion of the Python ecosystem has fueled two distinct but converging threats: adversaries increasingly target the software supply chain via the Python Package Index (PyPI), while also building evasive, cross-platform malicious binaries compiled from source code written in Python. Current program analysis techniques struggle to address this dual threat. Static analysis based tools are often blinded by runtime obfuscation and compiled bytecode, while dynamic analysis based ones are fragile, prone to evasion by environmental guardrails, and often terminates prematurely due to unsatisfied dependencies. To overcome these limitations, we present PyFEX, a resilient forced-execution engine. PyFEX explores a program's behavioral space systematically by forcing execution across all conditional branches to bypass evasion checks. To address the fragility of dynamic execution, it introduces a novel resilient crash recovery mechanism that synthesizes dummy objects to satisfy failed operations at the runtime, allowing analysis to proceed past fatal errors, and employs path merging to mitigate path explosion. PyFEX further incorporates an automated entry identification mechanism that proactively discovers and invokes dormant functions, exposing malicious logic hidden within uncalled APIs. To demonstrate the efficacy of this engine, we built PyFEXScan, a proof-of-concept malware detector built on top of PyFEX. Evaluated against both known malicious PyPI packages and real-world compiled binaries, PyFEX exposes critical behaviors missed by the existing state-of-the-art tools. In a live deployment on PyPI, PyFEXScan discovered 212 previously unknown malicious packages accounting for over 91,648 downloads, underscoring the necessity of resilient, exhaustive analysis for securing the Python ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang 等ASE 2023 · 被引用 31 次
- MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware AnalysisAbbas Naderi-Afooshteh, Yonghwi Kwon, Anh Nguyen-Tuong, Ali Razmjoo-Qalaei 等CCS 2019 · 被引用 18 次
- A Needle is an Outlier in a Haystack: Hunting Malicious PyPI Packages with Code ClusteringWentao Liang, Xiang Ling, Jingzheng Wu, Tianyue Luo 等ASE 2023 · 被引用 15 次
- Leveraging Large Language Models to Detect NPM Malicious PackagesNusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh 等ICSE 2025 · 被引用 8 次
- PyRadar: Towards Automatically Retrieving and Validating Source Code Repository Information for PyPI PackagesKai Gao, Weiwei Xu, Wenhao Yang, Minghui ZhouFSE 2024 · 被引用 7 次
相关 Paper
- Bad Snakes: Understanding and Improving Python Package Index Malware ScanningDuc-Ly Vu, Zachary Newman, John Speed MeyersICSE 2023 · 被引用 18 次
- Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining FrameworkWenbo Guo, Chengwei Liu, Ming Kang, Yiran Zhang 等USENIX Security 2026 · 被引用 1 次
- Uncovering Similar but Different Packages in PyPI and Potential Security ThreatsSunha Park, Soojin Han, Seunghoon WooFSE 2026
- PyXray: Practical Cross-Language Call Graph Construction through Object Layout AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Georgios Gousios, Zhendong Su 等ICSE 2026
- CrossFit: Demystifying VM Callback Bugs in InterpretersChibin Zhang, Qiang Liu, Mathias PayerFSE 2026
