Section 01
SocketAI Reproduction: Guide to the LLM-Powered Malicious npm Package Detection Tool
This article introduces the open-source reproduction project of the ICSE 2025 paper SocketAI. This tool implements malicious code detection for npm packages based on a three-stage LLM analysis workflow, supporting CodeQL pre-screening and full experimental data export. It aims to address the problem that traditional static analysis in the npm ecosystem struggles to handle new types of malicious attacks.