GuardDog is a CLI tool that allows to identify malicious PyPI and npm packages, Go modules, GitHub actions, or VSCode extensions. It runs a set of heuristics on the package source code (through ...
Abstract: Open-source, community-driven package repositories see thousands of malware packages each year, but do not currently run automated malware detection systems. In this work, we explore the ...
Total install time (download of files and installation of dependencies) should take less than an hour. Includes ipython notebooks and related metadata for analyzing LC-MS data of peptide variants to ...