{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T15:16:50Z","timestamp":1787239010129,"version":"build-2736575974"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3106600"],"award-info":[{"award-number":["2023YFB3106600"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472296"],"award-info":[{"award-number":["62472296"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Sichuan Science and Technology Program","award":["2024ZHCG0197"],"award-info":[{"award-number":["2024ZHCG0197"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Rel."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tr.2026.3676895","type":"journal-article","created":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T19:55:38Z","timestamp":1774468538000},"page":"1540-1553","source":"Crossref","is-referenced-by-count":1,"title":["Snake in the Grass: A Hybrid Detection Method Targeting Malicious PyPI Packages"],"prefix":"10.1109","volume":"75","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5871-946X","authenticated-orcid":false,"given":"Cheng","family":"Huang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4483-5427","authenticated-orcid":false,"given":"Yutong","family":"Zeng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8412-7695","authenticated-orcid":false,"given":"Genpei","family":"Liang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-5882-7322","authenticated-orcid":false,"given":"Zhen","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1509-704X","authenticated-orcid":false,"given":"Yutong","family":"Du","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946156"},{"key":"ref2","article-title":"Towards understanding and securing the OSS supply chain","author":"Duc","year":"2022"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468571"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106267"},{"key":"ref5","first-page":"245","article-title":"We dont need another hero?: The impact of heroes on software development","volume-title":"Proc. 40th Int. Conf. Softw. Eng.: Softw. Eng. Pract.","author":"Agrawal","year":"2018"},{"key":"ref6","article-title":"Why use Python for AI and machine learning","author":"Beklemysheva","year":"2021"},{"issue":"10","key":"ref7","first-page":"6","article-title":"Python current trend applications-an overview","volume":"6","author":"Saabith","year":"2019","journal-title":"Int. J. Adv. Eng. Res. Develop."},{"key":"ref8","article-title":"PyPI official repository is poisoned by request malicious packages","year":"2020"},{"key":"ref9","article-title":"Malware packages on PyPI","author":"ewdurbin","year":"2018"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87839-9_6"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00121"},{"issue":"4","key":"ref12","first-page":"83","article-title":"For good measure","volume":"45","author":"Deming","year":"2020","journal-title":"USENIX Patrons"},{"key":"ref13","article-title":"Suppy chain malware - detecting malware in package manager repositories","author":"Perica","year":"2019"},{"key":"ref14","article-title":"Malicious aptX Python package drops meterpreter shell, deletes netstat","year":"2023"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.3426281"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00052"},{"key":"ref17","first-page":"3765","article-title":"DONAPI: Malicious NPM packages detector using behavior sequence knowledge mapping","volume-title":"Proc. 33 rd USENIX Secur. Symp.","author":"Huang","year":"2024"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00135"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09737-2"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom53373.2021.00091"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/53990.53994"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3605770.3625212"},{"key":"ref23","article-title":"Python packages with malicious install-time behavior","author":"Ladisa","year":"2025"},{"key":"ref24","article-title":"Python packages with malicious import-time behavior","author":"Ladisa","year":"2025"},{"key":"ref25","article-title":"Built distribution","year":"2023"},{"key":"ref26","article-title":"Wheel","year":"2025"},{"key":"ref27","article-title":"Python packages with malicious runtime behavior","author":"Ladisa","year":"2025"},{"key":"ref28","article-title":"Guarddog is a CLI tool to identify malicious PyPI and NPM packages","author":"Labs","year":"2022"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00085"},{"key":"ref30","article-title":"Malware checks - warehouse documentation","year":"2020"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.23055"},{"key":"ref33","article-title":"Source archive","year":"2023"},{"key":"ref34","article-title":"Source distribution","year":"2023"},{"key":"ref35","article-title":"PEP 427the wheel binary package format 1.0","author":"Coghlan","year":"2021"},{"key":"ref36","article-title":"Top-level code environment","author":"Foundation","year":"2025"},{"key":"ref37","article-title":"Levenshtein distance","year":"2023"},{"key":"ref38","article-title":"Sensitive apis from MalOSS","author":"Duan","year":"2025"},{"key":"ref39","article-title":"Sensitive apis from MalOSS","year":"2025"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.09.024"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2958185"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3022432"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.17"},{"key":"ref44","volume-title":"Selinux NSAs Open Source Security Enhanced Linux","author":"McCarty","year":"2005"},{"key":"ref45","article-title":"Installing from local archives","year":"2025"},{"key":"ref46","article-title":"Alexa top 1 million sites","author":"Ghodke","year":"2022"},{"key":"ref47","article-title":"Top PyPI packages: A monthly dump of the 5,000 most-downloaded packages from PyPI","author":"Kemenade","year":"2018"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627138"},{"key":"ref49","article-title":"A fork of bandit tool with patterns to identifying malicious python code","author":"Vu","year":"2020"},{"key":"ref50","article-title":"OSS detect backdoor","year":"2019"},{"key":"ref51","article-title":"Bandit is a tool designed to find common security issues in python code","year":"2019"},{"key":"ref52","article-title":"apidev-coop","year":"2025"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI47803.2020.9308523"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2078195"},{"key":"ref55","article-title":"Pepy","author":"Sincraian","year":"2019"},{"key":"ref56","article-title":"Skydeo","year":"2025"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/sp46215.2023.10179304"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-025-10621-5"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104445"},{"key":"ref60","first-page":"1990","article-title":"Towards robust detection of open source software supply chain poisoning attacks in industry environments","volume-title":"Proc. 39th IEEE\/ACM Int. Conf. Automated Softw. Eng.","author":"Zheng","year":"2024"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2025.3599732"},{"key":"ref62","article-title":"Typosquatting in programming language package managers","author":"Tschacher","year":"2016"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00074"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678526"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3523262"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00073"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-NIER.2019.00012"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1016\/j.patter.2023.100773"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510104"}],"container-title":["IEEE Transactions on Reliability"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/24\/11317936\/11456189.pdf?arnumber=11456189","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:48:25Z","timestamp":1777492105000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11456189\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":70,"URL":"https:\/\/doi.org\/10.1109\/tr.2026.3676895","relation":{},"ISSN":["0018-9529","1558-1721"],"issn-type":[{"value":"0018-9529","type":"print"},{"value":"1558-1721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}