PDCG-RuleDetector: parameterized data-flow call graphs meet large language models for malicious NPM package detection
With the widespread use of open-source components in modern software development, reusing third-party code improves development efficiency while also intensifying security risks in the software supply chain. As the largest open-source package registry in the world, NPM (Node Package Manager) has become a primary target...