Version context and control construction in machine learning detection of malicious package updates across npm and PyPI
Open-source package registries such as npm and PyPI are increasingly targeted by software supply-chain attacks in which a trusted package is compromised through a later release. This study reconstructs each candidate release together with its immediate predecessor in npm and PyPI and evaluates machine-learning detectio...