PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 2, 20260 citationsOpen Access

CI-Guard: Static Analysis for Detecting Supply Chain Attacks in Package Managers

View Full Paper
AOAhmed Otsmane

Key Points

  • The aim is to enhance the detection of supply chain attacks in package management systems using static analysis.
  • Evaluated the tool on popular NPM and PyPI packages.
  • Improved methodology and detection patterns from the original version.
  • Refined evaluation results to assess performance.
  • Achieved zero false positives in detection.
  • Demonstrated strong detection performance against various attack patterns.

Abstract

This version extends the original preprint with improved methodology details,additional detection patterns, refined evaluation results, and minor corrections.The tool is evaluated on popular NPM and PyPI packages and demonstrates strongdetection performance with zero false positives. Source code: https://github.com/Otsmane-Ahmed/ci-supplychain-guard

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Ahmed Otsmane (2026) studied this question.

synapsesocial.com/papers/6980ff37c1c9540dea81200ehttps://doi.org/10.5281/zenodo.18442321
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Securing the Supply Chain: Automated Defenses Against Emerging Cyber Risks2025
  2. 2PDCG-RuleDetector: parameterized data-flow call graphs meet large language models for malicious NPM package detection2026
  3. 3GoSurf: Identifying Software Supply Chain Attack Vectors in Go2024
  4. 4Package Hallucinations as Phantoms in Open-source Software Supply Chains: An Empirical Security Analysis2026
  5. 5Securing Cloud-Native Software Supply Chains in the Presence of AI-Driven Threats2026