Korvyr: A Hybrid Graph Neural Network and Static-Analysis Prototype for Pre-Install npm Package Screening
Gianmarco Mazzella · Zenodo (CERN European Organization for Nuclear Research) · 2026
Malicious npm packages can execute code during installation, making pre-install screening a useful complement to retrospective vulnerability and indicator-based controls. This technical report presents Korvyr, an implemented research prototype that combines package-level graph features, static behavioral checks, manifest inspection, and metadata signals. JavaScript and MJS source files are represented as a Code Property Graph containing abstract-syntax, approximate control-flow, and lexical def-use edges. A four-layer edge-aware Graph Isomorphism Network produces a package score, while deterministic checks provide human-readable evidence. A calibrated decision policy maps these signals to clean, suspicious, or malicious outcomes. A local registry proxy can prevent a hard-blocked package from reaching npm's lifecycle execution stage. On a fixed, balanced development benchmark of 300 malicious and 300 benign packages, the current public configuration produced 264 true positives, 10 false positives, 36 false negatives, and 290 true negatives. This corresponds to 96.4% precision, 88.0% recall, and an F1 score of 0.920. These figures are calibration results, not independent estimates of production performance. The benchmark was reused during policy development, its 50% malicious prevalence is unrealistic, and the public repository excludes the downloaded corpus and trained checkpoint. The contribution is an end-to-end, inspectable research prototype and an empirical account of its development behavior. It is not a claim of production readiness or robustness against previously unseen attack families. Source code: https://github.com/gianmarcomaz/Korvyr