{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:X4XRTSII67ASGEO5ISMUNIPQIJ","short_pith_number":"pith:X4XRTSII","schema_version":"1.0","canonical_sha256":"bf2f19c908f7c12311dd449946a1f0425e7fa2a4129eaaf65f877693fffc0720","source":{"kind":"arxiv","id":"2503.00324","version":1},"attestation_state":"computed","paper":{"title":"DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Chadni Islam, Gowri Ramachandran, Raja Jurdak, Sk Tanzir Mehedi","submitted_at":"2025-03-01T03:20:42Z","abstract_excerpt":"Malicious Python packages make software supply chains vulnerable by exploiting trust in open-source repositories like Python Package Index (PyPI). Lack of real-time behavioral monitoring makes metadata inspection and static code analysis inadequate against advanced attack strategies such as typosquatting, covert remote access activation, and dynamic payload generation. To address these challenges, we introduce DySec, a machine learning (ML)-based dynamic analysis framework for PyPI that uses eBPF kernel and user-level probes to monitor behaviors during package installation. By capturing 36 rea"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.00324","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-01T03:20:42Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"48bc935c61eb06d490947335111edd9318268e08657ce190d2ac68c59e42c18d","abstract_canon_sha256":"f3aa6ecc5d36c1d4526dac92772ab4c3287ef34b8fcd4b05733317d2065a65c6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:22:20.781083Z","signature_b64":"ryYO8u/EERTXFcSvKnZ7Km8NuKk//iT8dDsaukZe0Hyw2YgNUv58dlEdJX+h3GvREXKdtj1nEBUazlTbpuAJCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bf2f19c908f7c12311dd449946a1f0425e7fa2a4129eaaf65f877693fffc0720","last_reissued_at":"2026-07-05T10:22:20.780470Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:22:20.780470Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Chadni Islam, Gowri Ramachandran, Raja Jurdak, Sk Tanzir Mehedi","submitted_at":"2025-03-01T03:20:42Z","abstract_excerpt":"Malicious Python packages make software supply chains vulnerable by exploiting trust in open-source repositories like Python Package Index (PyPI). Lack of real-time behavioral monitoring makes metadata inspection and static code analysis inadequate against advanced attack strategies such as typosquatting, covert remote access activation, and dynamic payload generation. To address these challenges, we introduce DySec, a machine learning (ML)-based dynamic analysis framework for PyPI that uses eBPF kernel and user-level probes to monitor behaviors during package installation. By capturing 36 rea"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.00324","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.00324/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.00324","created_at":"2026-07-05T10:22:20.780593+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.00324v1","created_at":"2026-07-05T10:22:20.780593+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.00324","created_at":"2026-07-05T10:22:20.780593+00:00"},{"alias_kind":"pith_short_12","alias_value":"X4XRTSII67AS","created_at":"2026-07-05T10:22:20.780593+00:00"},{"alias_kind":"pith_short_16","alias_value":"X4XRTSII67ASGEO5","created_at":"2026-07-05T10:22:20.780593+00:00"},{"alias_kind":"pith_short_8","alias_value":"X4XRTSII","created_at":"2026-07-05T10:22:20.780593+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07792","citing_title":"MOLOT System Card: Malicious Operational Logic Observation Transformer","ref_index":8,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ","json":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ.json","graph_json":"https://pith.science/api/pith-number/X4XRTSII67ASGEO5ISMUNIPQIJ/graph.json","events_json":"https://pith.science/api/pith-number/X4XRTSII67ASGEO5ISMUNIPQIJ/events.json","paper":"https://pith.science/paper/X4XRTSII"},"agent_actions":{"view_html":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ","download_json":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ.json","view_paper":"https://pith.science/paper/X4XRTSII","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.00324&json=true","fetch_graph":"https://pith.science/api/pith-number/X4XRTSII67ASGEO5ISMUNIPQIJ/graph.json","fetch_events":"https://pith.science/api/pith-number/X4XRTSII67ASGEO5ISMUNIPQIJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ/action/storage_attestation","attest_author":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ/action/author_attestation","sign_citation":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ/action/citation_signature","submit_replication":"https://pith.science/pith/X4XRTSII67ASGEO5ISMUNIPQIJ/action/replication_record"}},"created_at":"2026-07-05T10:22:20.780593+00:00","updated_at":"2026-07-05T10:22:20.780593+00:00"}