arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ProfMalPlus:通过静态-动态分析协同实现代理协调检测恶意NPM包

ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy

Yiheng Huang, Zhijia Zhao, Bihuan Chen, Susheng Wu, Zhuotong Zhou, Yiheng Cao, Kun Hu, Xin Hu, Xin Peng

arXiv 2607.13965首次发表:更新:

AI 中文总结

研究针对NPM包恶意代码检测问题,提出ProfMalPlus,结合对象敏感行为图与大语言模型推理,经多步骤提取安全切片并评估,对不确定情况增强证据后再评估,最终定位恶意代码,F1分数高且发现多个未知恶意包,性能优于现有检测器。

AI 中文摘要

开源软件易受供应链攻击,尤其是NPM包中的恶意代码。现有检测器存在诸多问题。本文提出ProfMalPlus,它将对象敏感行为图与带注释代码切片的协同大语言模型推理相结合。能识别安装命令和入口文件,构建相关图并提取安全切片,由本地和全局判断代理评估,对不确定情况进行第三方增强或动态增强,最后定位恶意代码片段。该方法F1分数达98.1%,优于现有检测器,还识别出597个未知恶意包。

英文摘要

Open source software is vulnerable to supply-chain attacks through transitive dependencies, especially malicious code injected into NPM packages. Existing detectors often inadequately model obfuscated behavior, overlook JavaScript's object-centric features, poorly coordinate static and dynamic analysis, and lose semantic information during behavior abstraction. We propose ProfMalPlus, a malicious NPM package detector combining object-sensitive behavior graphs with coordinated LLM reasoning over annotated code slices. It identifies installation commands and entry files, then constructs graphs capturing sensitive APIs, third-party calls, and unresolved calls. From these graphs, ProfMalPlus extracts security-relevant slices and adds inline static analysis evidence. Local judge agents independently assess each slice. Self-consistency consolidates repeated judgements to reduce LLM variance, while a global judge synthesizes their reports into an entry-level verdict. For undetermined cases, a router selects either third-party enrichment, which adds registry derived module and method semantics, or dynamic augmentation, which executes the package in a sandbox to resolve runtime dependent behavior. The enriched evidence is fed back for reassessment. Finally, a localization agent reports malicious code snippets with explanations. ProfMalPlus achieves a 98.1% F1-score, outperforming state-of-the-art detectors by 3.5% to 52.6%. It also identified 597 previously unknown malicious packages, all confirmed and removed from NPM.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑