Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Sunha Park, Soojin Han, Seunghoon Woo
摘要
In this study, we present a large-scale, in-depth study of package replication in PyPI. As a vital platform, PyPI streamlines Python package distribution for developers. However, beyond small-scale code cloning, we observe that many replicated packages exist on PyPI, which duplicate most of the codebase from existing packages. Such replication not only confuses developers but also propagates known vulnerabilities and enables the creation of new malicious packages. To address this issue, we comprehensively examine the characteristics and potential threats of replicated packages. Using one-third of the entire PyPI repository (200K packages), we investigate replication from three perspectives: replication of popular packages, vulnerable packages, and malicious packages. Our experiments reveal three critical findings about package replication in PyPI: (1) by identifying 1,361 replicated packages of the top 3K popular projects, we show that replication frequently redistributes substantial portions of existing packages under different maintainers; (2) by uncovering 256 previously unknown replicated vulnerable packages, we demonstrate that replication creates vulnerability blind spots that current detection tools rarely catch; (3) by analyzing 3,883 known malicious packages, we found that 186 (4.79%) replicated popular ones, and this pattern further led us to identify seven previously unknown replicated malicious packages, highlighting its role as an attack vector for malware distribution through minor modifications and code injection.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- CodeT5+: Open Code Large Language Models for Code Understanding and GenerationYue Wang, Hung Le, Akhilesh Gotmare, Nghi D. Q. Bui 等EMNLP 2023 · 被引用 339 次
- An Empirical Comparison of Pre-Trained Models of Source CodeChangan Niu, Chuanyi Li, Vincent Ng, Dongxiao Chen 等ICSE 2023 · 被引用 71 次
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate 等FSE 2021 · 被引用 53 次
- NIL: large-scale detection of large-variance clonesTasuku Nakagawa, Yoshiki Higo, Shinji KusumotoFSE 2021 · 被引用 41 次
相关 Paper
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang 等ASE 2023 · 被引用 31 次
- A Needle is an Outlier in a Haystack: Hunting Malicious PyPI Packages with Code ClusteringWentao Liang, Xiang Ling, Jingzheng Wu, Tianyue Luo 等ASE 2023 · 被引用 15 次
- Bloat beneath Python's Scales: A Fine-Grained Inter-Project Dependency AnalysisGeorgios-Petros Drosos, Thodoris Sotiropoulos, Diomidis Spinellis, Dimitris MitropoulosFSE 2024 · 被引用 6 次
- Insight: Exploring Cross-Ecosystem Vulnerability ImpactsMeiqiu Xu, Ying Wang, Shing-Chi Cheung, Hai Yu 等ASE 2022 · 被引用 12 次
- Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining FrameworkWenbo Guo, Chengwei Liu, Ming Kang, Yiran Zhang 等USENIX Security 2026 · 被引用 1 次
