DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
Mehedi, Sk Tanzir, Islam, Chadni, Ramachandran, Gowri, & Jurdak, Raja (2026) DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem. IEEE Transactions on Information Forensics and Security, 21, pp. 1316-1331.
|
Accepted Version
(PDF 5MB)
216023906. Available under License Creative Commons Attribution Non-commercial 4.0. |
Description
<p>Malicious Python packages make software supply chains vulnerable by exploiting trust in open-source repositories like Python Package Index (PyPI). Lack of real-time behavioral monitoring makes metadata inspection and static code analysis inadequate against advanced attack strategies such as typosquatting, covert remote access activation, and dynamic payload generation. To address these challenges, we introduce DySec, a machine learning (ML)-based dynamic analysis framework for PyPI that uses eBPF kernel and user-level probes to monitor behaviors during package installation. By capturing 36 real-time features–including system calls, network traffic, resource usage, directory access, and installation patterns–DySec detects threats like typosquatting, covert remote access activation, dynamic payload generation, and multiphase attack malware. We developed a comprehensive dataset of 14,271 Python packages, including 7,127 malicious sample traces, by executing them in a controlled isolated environment. Experimental results demonstrate that DySec achieves 96% detection accuracy with an ML inference latency of <0.5s after dynamic feature extraction, reducing false negatives by 78.65% compared to static analysis and 82.24% compared to metadata analysis. During the evaluation, DySec flagged eleven packages that PyPI classified as benign. A manual analysis, including installation behavior inspection, confirmed six of them as malicious. These findings were reported to PyPI maintainers, resulting in the removal of four packages. DySec bridges the gap between reactive traditional methods and proactive, scalable threat mitigation in open-source ecosystems by uniquely detecting malicious install-time behaviors.</p>
Impact and interest:
Citation counts are sourced monthly from Scopus and Web of Science® citation databases.
These databases contain citations from different subsets of available publications and different time periods and thus the citation count from each is usually different. Some works are not in either database and no count is displayed. Scopus includes citations from articles published in 1996 onwards, and Web of Science® generally from 1980 onwards.
Citations counts from the Google Scholar™ indexing service can be viewed at the linked Google Scholar™ search.
Full-text downloads:
Full-text downloads displays the total number of times this work’s files (e.g., a PDF) have been downloaded from QUT ePrints as well as the number of downloads in the previous 365 days. The count includes downloads for all files if a work has more than one.
| ID Code: | 262864 | ||||||
|---|---|---|---|---|---|---|---|
| Item Type: | Contribution to Journal (Journal Article) | ||||||
| Refereed: | Yes | ||||||
| ORCID iD: |
|
||||||
| Additional Information: | Publisher Copyright: © 2005-2012 IEEE. | ||||||
| Measurements or Duration: | 16 pages | ||||||
| Keywords: | Dynamic analysis, malicious detection, PyPI ecosystem, software supply chain/supply chain security | ||||||
| DOI: | 10.1109/TIFS.2026.3654388 | ||||||
| ISSN: | 1556-6013 | ||||||
| Pure ID: | 216023906 | ||||||
| Divisions: | ?? 1469440 ?? Current > QUT Faculties and Divisions > Faculty of Science Current > Schools > School of Computer Science Current > Schools > School of Information Systems |
||||||
| Copyright Owner: | Consult author(s) regarding copyright matters | ||||||
| Copyright Statement: | © 20XX IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.<br/><br/>It is a condition of access that users recognise and abide by the legal requirements associated with these rights. If you believe that this work infringes copyright please provide details by email to qut.copyright@qut.edu.au | ||||||
| Deposited On: | 28 Jan 2026 07:19 | ||||||
| Last Modified: | 11 Sep 2026 19:15 |
Export: EndNote | Dublin Core | BibTeX
Repository Staff Only: item control page