IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
Wenbo Guo, Chengwei Liu, Limin Wang, Yiran Zhang, Jiahui Wu, Zhengzi Xu, Yang Liu

TL;DR
IntelliRadar is a comprehensive platform that leverages web scraping and large language models to detect and compile malicious software packages from unstructured sources, significantly improving early detection and coverage over existing databases.
Contribution
We developed IntelliRadar, a novel platform combining exhaustive web searches and LLMs to identify malicious packages, enhancing detection coverage and timeliness beyond current tools.
Findings
Constructed a database of 34,313 malicious packages with high precision (97.91%).
Identified 7,542 more malicious packages than OSV and 12,684 more than Snyk.
Detected and confirmed 1,981 malicious packages in downstream registries.
Abstract
Malicious packages in public registries pose serious threats to software supply chain security. While current software component analysis (SCA) tools rely on databases like OSV and Snyk to detect these threats, these databases suffer from delayed updates and incomplete coverage. However, they miss intelligence from unstructured sources like social media and developer forums, where new threats are often first reported. This delay extends the lifecycle of malicious packages and increases risks for downstream users. To address this, we developed a novel and comprehensive approach to construct a platform IntelliRadar to collect disclosed malicious package names from unstructured web content. Specifically, by exhaustively searching and snowballing the public sources of malicious package names, and incorporating large language models (LLMs) with domain-specialized Least to Most prompts,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsRecycling and Waste Management Techniques · Manufacturing Process and Optimization · Flexible and Reconfigurable Manufacturing Systems
