Large-scale scan found 2,289 malicious Go module versions and showed 99.4% remained retrievable via proxy after GitHub takedowns.
event-stream incident report
2 Pith papers cite this work. Polarity classification is still indexing.
2
Pith papers citing it
fields
cs.CR 2years
2026 2verdicts
UNVERDICTED 2representative citing papers
Proposes cryptographic registry identity, dual-signature model, and authoritative namespace binding to create three defense layers against dependency confusion.
citing papers explorer
-
Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild
Large-scale scan found 2,289 malicious Go module versions and showed 99.4% remained retrievable via proxy after GitHub takedowns.
-
Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems
Proposes cryptographic registry identity, dual-signature model, and authoritative namespace binding to create three defense layers against dependency confusion.