March 14, 2024, 4:11 a.m. | Cheng Huang (Sichuan University), Nannan Wang (Sichuan University), Ziyan Wang (Sichuan University), Siqi Sun (Sichuan University), Lingzi Li (Sichuan

cs.CR updates on arXiv.org arxiv.org

arXiv:2403.08334v1 Announce Type: new
Abstract: With the growing popularity of modularity in software development comes the rise of package managers and language ecosystems. Among them, npm stands out as the most extensive package manager, hosting more than 2 million third-party open-source packages that greatly simplify the process of building code. However, this openness also brings security risks, as evidenced by numerous package poisoning incidents.
In this paper, we synchronize a local package cache containing more than 3.4 million packages in …

arxiv building code cs.cr detector development ecosystems hosting knowledge language malicious malicious npm manager managers mapping npm package package manager package managers packages party process simplify software software development third third-party

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, VA, Arlington (1550 Crystal Dr Suite 300) non-client

Invoice Compliance Reviewer

@ AC Disaster Consulting | Fort Myers, Florida, United States - Remote

Technical Program Manager II - Compliance

@ Microsoft | Redmond, Washington, United States

Head of U.S. Threat Intelligence / Senior Manager for Threat Intelligence

@ Moonshot | Washington, District of Columbia, United States

Customer Engineer, Security, Public Sector

@ Google | Virginia, USA; Illinois, USA