3 ms·
Is it easy to find a list of packages that have been pulled from python/npm in the past? Would be interesting to train some models against it
by jb_s 4y ago
Is it easy to find a list of packages that have been pulled from python/npm in the past? Would be interesting to train some models against it
- karxxm 4y agoWhat would the input to such a model be? The malicious code snippets? Or do you want to classify packages according to other meta data?
- jb_s 4y agoYeah. I was wondering how easy it would be to classify using a language model/models. ALthough I don't know how it'd work with binary blobs, multiple languages, etc. I think certain things would be picked up pretty easily e.g. obfuscated code would be a pretty loud feature, but subtle stuff might be undetected and generally I can't see the model being super accurate.
- ashishbijlani 4y agoSure. Please email me (in profile) for the list. You can also look at the following resources for malware samples: 1. https://github.com/IQTLabs/software-supply-chain-compromises https://github.com/IQTLabs/software-supply-chain-compromises 2. https://github.com/rsc-dev/pypi_malware https://github.com/rsc-dev/pypi_malware 3. https://github.com/osssanitizer/maloss/blob/master/malware/README.md https://github.com/osssanitizer/maloss/blob/master/malware/R...