Metadata Compressibility and Evaluation Bias in Malicious Package Detection for NPM and PyPI
Malicious packages in open source-software supply chains are a growing security concern, yet machine learning detectors built on registry metadata are difficult to interpret and are typically evaluated under protocols susceptible to data leakage. We construct a dataset of 3330 package versions from NPM and PyPI in whic...