OSPtrack: A Labeled Dataset Targeting Simulated Execution of Open-Source Software
收藏资源简介:
This release extends the original OSPtrack dataset with additional malicious open-source packages collected from multiple public sources. Many of these packages are no longer available from their original package registries. To improve runtime coverage, archived package files are matched by ecosystem, package name, and version, and replayed locally using the OpenSSF Package Analysis framework in an isolated sandbox. The release includes: Additional malicious package metadata and archived samples; Runtime analysis reports generated from locally replayed packages; Static and dynamic traces, including file, process, command, DNS, socket, and network activities; Execution status and provenance information for reproducibility; Updated scripts for package matching, local replay, and result extraction. This dataset supports research on malicious package behavior, software supply-chain security, cross-ecosystem analysis, and the limitations caused by unavailable or removed registry packages.



