2026· International Conference on Security and Cryptography· pp. 1073-1080· 0 citations· 22 references
Computer Science
TL;DR
It is demonstrated that SCA warnings deviate under obfuscation and provide a practical proxy indicator for distinguishing obfuscated code from human-readable code.
Abstract
: This study investigates whether the output of Static Code Analysis (SCA) tools can serve as a proxy indicator for identifying obfuscated JavaScript. Two datasets are analyzed in their original and obfuscated forms: a controlled pilot dataset focused on common malicious patterns and a larger Kaggle dataset of approximately 1900 real-world JavaScript files. Four SCA tools are applied to both datasets: SonarQube, ESLint, NodeJsScan, and JSHint. The outputs are normalized into a unified feature schema, and pre/post-obfuscation deviance is quantified through issue counts and Kernel Density Estimation (KDE) of warnings normalized by file size and line count. Results show large and consistent increases in issue counts for ESLint and JSHint, substantial rises for SonarQube, and unstable shifts for NodeJsScan. The KDE analysis strengthens the proxy indicator’s effectiveness beyond raw counts by confirming that normalized warning intensity rises after obfuscation for SonarQube and JSHint. These patterns demonstrate that SCA warnings deviate under obfuscation and provide a practical proxy indicator for distinguishing obfuscated code from human-readable code.
As a crucial component of websites, JavaScript is one of the most common attack payloads on malicious websites. Although many methods for detecting malicious JavaScript have been proposed, obfuscation techniques make it difficult for previous approaches to detect disguised malicious JavaScript effectively. To address t...
Malicious npm package detection tools now leverage LLMs'semantic understanding of source code to detect malicious intent at scale. This capability has proven invaluable in identifying packages involved in recent supply-chain attacks such as Shai-Hulud. However, threat actors exploit the limited context windows of LLMs...
Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al.· 0 citations
A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.
Wen-Yu Xu, Anders Møller· Proceedings of the 41st IEEE...· 0 citations
A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.
Investigating Behavior Trees (BTs) as an alternative intermediate representation for LLM-based vulnerability detection suggests that BTs can provide a compact and useful structured representation for vulnerability detection with quantized, locally deployable LLMs.
Python package security is largely source-centric, yet Python runtimes can execute bytecode directly through .pyc files, compiled-only modules, and marshalled code objects, creating an inspection-execution gap. We present an empirical study of Python bytecode as a security artifact. We measure bytecode exposure in PyPI...
Bai-Hong Chen, Tian Xie, Wen Li· 1 citation· ⚡1
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.