Skip to content

Scientific Paper: SpiderScan - #3103

Open
j3nnr wants to merge 4 commits into
KTH:2026from
j3nnr:2026
Open

j3nnr wants to merge 4 commits into
KTH:2026from
j3nnr:2026

Conversation

@j3nnr

@j3nnr j3nnr commented Oct 1, 2026 •

Copy link
Copy Markdown

Assignment Proposal

SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and Matching

Names and KTH ID

Deadline

  • Week 6

Category

  • Scientific paper

Description

Modern software development relies heavily on third-party packages and dependencies, making package ecosystems an attractive target for software supply chain attacks. Malicious packages can be difficult to detect because individual behaviors, such as accessing files or communicating over a network, can occur in both legitimate and malicious software.

The paper we have chosen to present, “SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and Matching”, presents an approach for detecting malicious packages in the npm ecosystem. Instead of considering suspicious API calls only in isolation, SpiderScan models their relationships using behavior graphs that capture control flow and data dependencies. It then matches suspicious behavior against known malicious behavior patterns and uses additional verification to reduce false positives.

During the presentation we cover the problem of malicious packages, explain SpiderScan’s graph-based approach and evaluation. Discuss its DevSecOps and dependency-management implications, and critically compare its limitations with related approaches such as ProfMal and MalGuard.

Relevance

Third-party dependencies are an important part of modern DevOps pipelines, but they also introduce software supply chain security risks. Detecting malicious dependencies before they can compromise development, build, or deployment environments is therefore relevant to DevSecOps. SpiderScan addresses this problem by providing an automated approach for analyzing npm packages and identifying potentially malicious behavior.

@ericcornelissen ericcornelissen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The proposal looks good but please resolve the CI failures.

@MiTO-X2

MiTO-X2 commented Oct 3, 2026

Copy link
Copy Markdown

We would like to do feedback on your paper if that is possible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants