malwaresupply-chain-attacktyposquattingobfuscationresearch

Ohm et al. — Backstabber's Knife Collection, DIMVA

Provides a definitive taxonomy of open-source malware 'triggers' and 'evasion' techniques, identifying install-time execution and typosquatting as the primary delivery vectors.

Summary

A comprehensive analysis of 174 malicious packages across npm, PyPI, and RubyGems (2015-2019) reveals that 56% of attacks trigger malicious behavior on installation, while 43% trigger at runtime. Most packages (61%) leverage typosquatting, with an average Levenshtein distance of 2.3 from the target. The primary objective for 55% of packages is data exfiltration (e.g., /etc/passwd, SSH keys, npmrc), while 34% act as droppers for second-stage payloads. Alarmingly, 41% of malware employs conditional execution—checking application state (e.g., production mode) or dependency tree nodes—to evade sandbox detection. The research identifies 21 'clusters' of reused malicious code, indicating industrialized campaigns that operate across multiple programming languages and registries, often using obfuscation (49%) to hide their intent.

Related Checks

PACKAGE_ACTIVE_MALWARE

The research analyzed 174 real-world malicious packages, confirming that data exfiltration and backdoors are the most common objectives of supply chain attackers.

Adverse Outcome

compromise of credentials and permanent loss of sensitive system data through intentionally malicious dependencies

Because

identifying active malware is the final and most critical control for supply chain security, validated by the 1,300% growth in repository threats.

PACKAGE_INSTALL_SCRIPTS

56% of the analyzed malware triggered its payload during the installation phase, often leveraging setup.py or package.json lifecycle hooks.

Adverse Outcome

unauthorized execution of malicious shell commands during the standard dependency installation process

Because

install-time execution is the statistically dominant delivery vector for open-source malware, making the detection of install scripts a primary risk signal.

Gaps Analysis

Evidence

41% of the packages check for a condition before triggering... Application State, Dependency Tree, Operating System... done to find profitable targets and evade sandboxing.

Blind Spot

Risk Guard evaluates technical signals but does not perform 'Evasion Detection' to identify code that deliberately sleeps or hides during sandbox analysis.

Actionable Capability

Risk Guard would be better if it flagged 'Environmental Checks' (e.g., detecting CI, OS, or specific dependencies) that are common markers for malware evasion.

← Previous Next →