About the Dataset
The Backstabber's Knife Collection is a unique dataset meticulously curated to provide insights into malicious open source software components observed in real-world attacks starting 2015. Sourced from popular package repositories like npm, PyPI, and RubyGems, this collection serves as an invaluable asset for researchers, security professionals, and developers mitigating software supply chain risks.
Key Features
Engineered for robust open-source security analytics
Real-World Attacks
Contains samples from actual attacks, offering practical insights into prevalent malicious techniques.
Multi-Ecosystem Coverage
Includes malicious packages from npm, PyPI, RubyGems, and more, reflecting diverse attack vectors.
Research Backing
Based on research presented in a scientific paper, ensuring rigorous data quality and practical relevance.
Explore Malicious Package Examples
Browse malicious packages included in the dataset, dynamically filtered and categorized by ecosystem.
Media Coverage
Articles and academic mentions of the Backstabber's Knife Collection.
How to Request Access
The Backstabber's Knife Collection is freely available for verified security research and academic evaluation purposes.
Please transmit an email request to ohm[at]cs.uni-bonn.de from your institution’s official email infrastructure.
Your request must detail:
- Your core research objectives & framework methodology
- Your active institutional GitHub user identity
- Note: Inquiries originating from anonymous or public providers (Gmail/Yahoo/etc.) cannot be authorized.
Resources & Links
Citation Information
If you employ this ecosystem dataset within academic or industrial publications, kindly credit using the following schema:
@inproceedings{ohm2020backstabber,
title={Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks},
author={Ohm, Marc and Plate, Henrik and Sykosch, Arnold and Meier, Michael},
booktitle={DIMVA},
year={2020},
organization={Springer}
}