DistillGuard: Malicious NPM Package Detection and API Attack Chain Analysis via Static Graph and LLM Distillation
cs.CR
Submitted: 2026-09-24
Updated: 2026-09-24
Code: https://github.com/microsoft/OSSGadget
Terminology
Sources
- DeepSeek-V3 Technical Report
- Kimi K2: Open Agentic Intelligence
- Distilling the Knowledge in a Neural Network
- Qwen3 Technical Report
- OpenAI GPT-5 System Card
- How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study
- PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs