Uppsats

Predicting vulnerability of npm packages using metadata analysis

Master-uppsats

KTH/Skolan för elektroteknik och datavetenskap (EECS)

Publicerad: 2026

Språk: Engelska

Sammanfattning

Cyber attacks are becoming more frequent. The prevalence of software supply chains means a compromised package high up in the chain can affect many victims. Software registries such as npmjs.com contain large amounts of packages. In order to detect malicious and vulnerable packages, code analysis is often used. However, it could be possible to instead use the metadata of packages to predict whether or not they are vulnerable. To attempt this, the npm database was downloaded and pre-processed to generate metadata factors that could be examined. Then, a ground-truth was established using the GitHub Security Advisory database. Afterwards, machine learning models were trained on the metadata using supervised learning. The models showed weak classification ability, achieving a best F1 score of 0.2482 with the LightGBM model. The most important metadata features were tied to the popularity and age of the package, which are of little use when attempting to predict unknown vulnerabilities. Nonetheless, there is little research previous in this area, and none on the npm database.

Information

Författare
Sjölander, Emil
Lärosäte / institution
KTH/Skolan för elektroteknik och datavetenskap (EECS)
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.