Malicious Packages Lurking in User-Friendly Python Package Index

Genpei Liang, Xiangyu Zhou, Qingyu Wang, Yutong Du, Cheng Huang · 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) · 2021

Python has gradually become one of the most important programming languages through artificial intelligence's development. PIP, a package management tool for Python, offers one-click installation, allowing developers to utilize other people's code to speed up development. However, any registered member can easily upload packages to the repository that stores third-party packages. This functionality is used by attackers to poison the package index, i.e., to publish enormous malicious pip packages for installing backdoor, gathering information, etc. To know the situation of third-party packages in the Python community ecosystem, we establish the criteria for judging packages' suspicious or malicious behavior by analyzing the code logic in disclosed malicious packages. With the gained findings, we propose and implement Pip Poisoning Detector (PPD), an approach based on anomaly detection. PPD evaluated 228,723 packages, and after human inspection, we found 63 malicious and 238 suspicious ones among the output 5,699 results. The experimental results prove that our approach is effective and can significantly reduce review workload by 97.51%.

Read the paper · More papers on PaperTik