DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem

, , , & (2026) DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem. IEEE Transactions on Information Forensics and Security, 21, pp. 1316-1331.

View at publisher

Description

<p>Malicious Python packages make software supply chains vulnerable by exploiting trust in open-source repositories like Python Package Index (PyPI). Lack of real-time behavioral monitoring makes metadata inspection and static code analysis inadequate against advanced attack strategies such as typosquatting, covert remote access activation, and dynamic payload generation. To address these challenges, we introduce DySec, a machine learning (ML)-based dynamic analysis framework for PyPI that uses eBPF kernel and user-level probes to monitor behaviors during package installation. By capturing 36 real-time features–including system calls, network traffic, resource usage, directory access, and installation patterns–DySec detects threats like typosquatting, covert remote access activation, dynamic payload generation, and multiphase attack malware. We developed a comprehensive dataset of 14,271 Python packages, including 7,127 malicious sample traces, by executing them in a controlled isolated environment. Experimental results demonstrate that DySec achieves 96% detection accuracy with an ML inference latency of <0.5s after dynamic feature extraction, reducing false negatives by 78.65% compared to static analysis and 82.24% compared to metadata analysis. During the evaluation, DySec flagged eleven packages that PyPI classified as benign. A manual analysis, including installation behavior inspection, confirmed six of them as malicious. These findings were reported to PyPI maintainers, resulting in the removal of four packages. DySec bridges the gap between reactive traditional methods and proactive, scalable threat mitigation in open-source ecosystems by uniquely detecting malicious install-time behaviors.</p>

Impact and interest:

3 citations in Scopus
0 citations in Web of Science®
Search Google Scholar™

Citation counts are sourced monthly from Scopus and Web of Science® citation databases.

These databases contain citations from different subsets of available publications and different time periods and thus the citation count from each is usually different. Some works are not in either database and no count is displayed. Scopus includes citations from articles published in 1996 onwards, and Web of Science® generally from 1980 onwards.

Citations counts from the Google Scholar™ indexing service can be viewed at the linked Google Scholar™ search.

Full-text downloads:

148 since deposited on 27 Jan 2026
148 in the past twelve months

Full-text downloads displays the total number of times this work’s files (e.g., a PDF) have been downloaded from QUT ePrints as well as the number of downloads in the previous 365 days. The count includes downloads for all files if a work has more than one.

ID Code: 262864
Item Type: Contribution to Journal (Journal Article)
Refereed: Yes
ORCID iD:
Mehedi, Sk Tanzirorcid.org/0000-0003-4435-7856
Ramachandran, Gowriorcid.org/0000-0001-5944-1335
Jurdak, Rajaorcid.org/0000-0001-7517-0782
Additional Information: Publisher Copyright: © 2005-2012 IEEE.
Measurements or Duration: 16 pages
Keywords: Dynamic analysis, malicious detection, PyPI ecosystem, software supply chain/supply chain security
DOI: 10.1109/TIFS.2026.3654388
ISSN: 1556-6013
Pure ID: 216023906
Divisions: ?? 1469440 ??
Current > QUT Faculties and Divisions > Faculty of Science
Current > Schools > School of Computer Science
Current > Schools > School of Information Systems
Copyright Owner: Consult author(s) regarding copyright matters
Copyright Statement: © 20XX IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.<br/><br/>It is a condition of access that users recognise and abide by the legal requirements associated with these rights. If you believe that this work infringes copyright please provide details by email to qut.copyright@qut.edu.au
Deposited On: 28 Jan 2026 07:19
Last Modified: 11 Sep 2026 19:15