Thumbnail for Replication Code for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem"

Replication Code for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem"

Important usage condition: Use and redistribution are governed by MIT. Review and comply with the license before using the data.
Persistent identifier
doi:10.60507/FK2/TNJHGT
Published version
1.0
Publication date
2026-01-30
License
MIT

Description

Scripts for reproducing cache files in Python packages. This includes an automated Docker-based setup for running old Python versions with bytecode compilation and tools for automatic and manual cache file comparisons. Additionally, proofs of concept are included

Creators

Keywords

Python, Cache, Software Supply Chain

Files

Before downloading: Use and redistribution are governed by MIT. Review and comply with the license before using the data.
FileTypeBytesChecksum
uv.lockapplication/octet-stream16615MD5 596279b871d705276c689a16adfc5115
models.pytext/x-python13296MD5 b99d27aa504df641039d7e55a993a193
python_37_314.pytext/x-python1241MD5 5131a3c9feec1fc0329ff3690b8a1fe1
README.mdtext/markdown408MD5 ccd424cbd3ceb220a5cae5d9c5e0746a
main.pytext/x-python30MD5 5390c0e270120a9b5fe81b1844420c1a
main.pytext/x-python52MD5 2058ef0220d1e3d523b6c3a83f616023
rich_313_parser.pytext/x-python3063MD5 b0167b0632df975a781d4178ec46d154
analyzer.pytext/x-python1144MD5 3b32755ab51dfa88318f07ad8a194bf5
table-synthesis-GenerateTable.cpython-310.pycapplication/octet-stream6756MD5 d5a66993666520fd7126f9bba58933c9
gator-core-__init__.cpython-311.pycapplication/octet-stream1180MD5 2c59180091d51b4434cf2755cf5aa3d6
python_26_36.pytext/x-python1299MD5 317dd6596b9bc5d11798df6976aaecb7
Cargo.tomlapplication/octet-stream331MD5 ab8e0b61860bd5c3dceb2661c8e88861
Cargo.lockapplication/octet-stream23949MD5 f24343a41dae8ba17805536c023b61d9
config.tomlapplication/octet-stream128MD5 5ad3d896a5d8f8bf5801550a26180fff
README.mdtext/markdown466MD5 38f368fb4adf02e4a273a035410f37e8
README.mdtext/markdown1342MD5 239ff821bb2060572e14a3636cfe59ad
evaluate.pytext/x-python5498MD5 f7ff00bc21f8c4fb1f436be195a96cb3
USAGE.mdtext/markdown625MD5 07600ee6d2f759ebf6a419e64eaca3fd
README.mdtext/markdown1832MD5 cc67966365097d4f8a1e8311f5e403a8
1-cleanup-data.pytext/x-python1770MD5 632421716f9314618491b70537bbdf6e
3-analyze-results.pytext/x-python6745MD5 be44b12d0261aabd858e8454fa927171
2-recreate-cache.pytext/x-python31498MD5 7bfd8f4549a4498b215d2e49ed1592c9
README.mdtext/markdown708MD5 23d705ed04ff6e5593cecd780dbad214
rich_313_parser.pytext/x-python3063MD5 b0167b0632df975a781d4178ec46d154
__init__.pytext/x-python0MD5 d41d8cd98f00b204e9800998ecf8427e
main.rsapplication/rls-services+xml3104MD5 1670000c27a7102edf7c8758b4ef363b
python_37_314.pytext/x-python769MD5 54a6faaf6df539403f2e0b5811a839ae
README.mdtext/markdown1182MD5 e9d7b47edbd96a88f439110db34dda36
__init__.pytext/x-python0MD5 d41d8cd98f00b204e9800998ecf8427e
python_26_31.pytext/x-python311MD5 08864ccb7efb6582773aabb8b4ba4ac7
python_32_36.pytext/x-python516MD5 38e6f2a6823b3b7e74ecfa5f95b3336c
extract-release-table.pytext/x-python984MD5 60940983cf502770b1e05ec9207f5543
magic-tabletext/plain; charset=US-ASCII11050MD5 8505cb8d42f6a86896375752781138db
extract-magic-table.pytext/x-python853MD5 96466e5f09844ece96281bddf4a338e5
scan_packages_for_cache_files.pytext/x-python5930MD5 4895e05b5d908a517f88371c76eb3bf4
malicious.pytext/x-python38MD5 79284666664c1e25b49eda52ff70eccd
compile_and_poison.pytext/x-python1721MD5 f44bdf0f76a7f40bb248546ca91fbfe6
MANIFEST.intext/plain59MD5 e881e74dc0e133ecccc964f4591b81e0
__init__.pytext/x-python0MD5 d41d8cd98f00b204e9800998ecf8427e
benign.pytext/x-python39MD5 021ff7b61b169c06212b627ccc3c8307
python_37_314.pytext/x-python1241MD5 5131a3c9feec1fc0329ff3690b8a1fe1
gator-core-__init__-3.11.13.pycapplication/octet-stream1276MD5 f5d2e26736b55da268f5dd48c106e73a
table-synthesis-GenerateTable-3.10.18.pycapplication/octet-stream6784MD5 b64fe185ced83aa8146a4c9d2d12a5eb
pyproject.tomlapplication/toml389MD5 8d090e615762f155a9b96eb24053b904
README.mdtext/markdown3530MD5 4466afbe8fa575ca11bf2aa699a20537
README.mdtext/markdown2866MD5 0e47fc900174635cab947e93335cb86e
readme.txttext/plain4594MD5 c514ad69f947e12840623f0e17458485
prepare.shapplication/x-shellscript983MD5 c2898eca22b71ed242944f8df904424f
pyproject.tomlapplication/toml390MD5 78901f870a1ae80963e9751dc22c9fce
README.mdtext/markdown193MD5 e57800e4d7a7a2672c946994731d916e
pyproject.tomlapplication/toml195MD5 250b03649f41a107784886f04056b12b
pyproject.tomlapplication/toml201MD5 5b197d172f50d8141d9de4e1fb930845

Citation

Ohm, Marc; Pohl, Timo; Swierzy, Ben; Meier, Michael, 2026-01-30, Replication Code for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem", doi:10.60507/FK2/TNJHGT, V1.0

Additional Dataverse fields

Export metadata

Static metadata exports available for this published dataset version:

Complete Dataverse metadata

Expected crawler behaviour

Use a stable, truthful User-Agent with product/version and a working contact URL. Across all IP addresses and HTTP connections used by one crawler identity, allow no more than 5 requests in flight and wait at least 20 seconds between request starts. Crawl URLs listed in the catalog sitemap, including file pages and download URLs when they are published, use conditional requests, honor Retry-After, and apply exponential backoff after errors.

The welcome page may link to the interactive repository for human navigation. Automated clients must not treat that human link as a catalog crawl target.

Read the live machine-readable crawler policy before and during a crawl. Stop crawling when it reports CPU or memory utilization at or above 80% and 80% respectively.