Replication Code for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem"
Open this dataset in the live repository
- Persistent identifier
- doi:10.60507/FK2/TNJHGT
- Published version
- 1.0
- Publication date
- 2026-01-30
- License
- MIT
Description
Scripts for reproducing cache files in Python packages. This includes an automated Docker-based setup for running old Python versions with bytecode compilation and tools for automatic and manual cache file comparisons. Additionally, proofs of concept are included
Creators
- Ohm, Marc
- Pohl, Timo
- Swierzy, Ben
- Meier, Michael
Keywords
Python, Cache, Software Supply Chain
Files
| File | Type | Bytes | Checksum |
|---|---|---|---|
| uv.lock | application/octet-stream | 16615 | MD5 596279b871d705276c689a16adfc5115 |
| models.py | text/x-python | 13296 | MD5 b99d27aa504df641039d7e55a993a193 |
| python_37_314.py | text/x-python | 1241 | MD5 5131a3c9feec1fc0329ff3690b8a1fe1 |
| README.md | text/markdown | 408 | MD5 ccd424cbd3ceb220a5cae5d9c5e0746a |
| main.py | text/x-python | 30 | MD5 5390c0e270120a9b5fe81b1844420c1a |
| main.py | text/x-python | 52 | MD5 2058ef0220d1e3d523b6c3a83f616023 |
| rich_313_parser.py | text/x-python | 3063 | MD5 b0167b0632df975a781d4178ec46d154 |
| analyzer.py | text/x-python | 1144 | MD5 3b32755ab51dfa88318f07ad8a194bf5 |
| table-synthesis-GenerateTable.cpython-310.pyc | application/octet-stream | 6756 | MD5 d5a66993666520fd7126f9bba58933c9 |
| gator-core-__init__.cpython-311.pyc | application/octet-stream | 1180 | MD5 2c59180091d51b4434cf2755cf5aa3d6 |
| python_26_36.py | text/x-python | 1299 | MD5 317dd6596b9bc5d11798df6976aaecb7 |
| Cargo.toml | application/octet-stream | 331 | MD5 ab8e0b61860bd5c3dceb2661c8e88861 |
| Cargo.lock | application/octet-stream | 23949 | MD5 f24343a41dae8ba17805536c023b61d9 |
| config.toml | application/octet-stream | 128 | MD5 5ad3d896a5d8f8bf5801550a26180fff |
| README.md | text/markdown | 466 | MD5 38f368fb4adf02e4a273a035410f37e8 |
| README.md | text/markdown | 1342 | MD5 239ff821bb2060572e14a3636cfe59ad |
| evaluate.py | text/x-python | 5498 | MD5 f7ff00bc21f8c4fb1f436be195a96cb3 |
| USAGE.md | text/markdown | 625 | MD5 07600ee6d2f759ebf6a419e64eaca3fd |
| README.md | text/markdown | 1832 | MD5 cc67966365097d4f8a1e8311f5e403a8 |
| 1-cleanup-data.py | text/x-python | 1770 | MD5 632421716f9314618491b70537bbdf6e |
| 3-analyze-results.py | text/x-python | 6745 | MD5 be44b12d0261aabd858e8454fa927171 |
| 2-recreate-cache.py | text/x-python | 31498 | MD5 7bfd8f4549a4498b215d2e49ed1592c9 |
| README.md | text/markdown | 708 | MD5 23d705ed04ff6e5593cecd780dbad214 |
| rich_313_parser.py | text/x-python | 3063 | MD5 b0167b0632df975a781d4178ec46d154 |
| __init__.py | text/x-python | 0 | MD5 d41d8cd98f00b204e9800998ecf8427e |
| main.rs | application/rls-services+xml | 3104 | MD5 1670000c27a7102edf7c8758b4ef363b |
| python_37_314.py | text/x-python | 769 | MD5 54a6faaf6df539403f2e0b5811a839ae |
| README.md | text/markdown | 1182 | MD5 e9d7b47edbd96a88f439110db34dda36 |
| __init__.py | text/x-python | 0 | MD5 d41d8cd98f00b204e9800998ecf8427e |
| python_26_31.py | text/x-python | 311 | MD5 08864ccb7efb6582773aabb8b4ba4ac7 |
| python_32_36.py | text/x-python | 516 | MD5 38e6f2a6823b3b7e74ecfa5f95b3336c |
| extract-release-table.py | text/x-python | 984 | MD5 60940983cf502770b1e05ec9207f5543 |
| magic-table | text/plain; charset=US-ASCII | 11050 | MD5 8505cb8d42f6a86896375752781138db |
| extract-magic-table.py | text/x-python | 853 | MD5 96466e5f09844ece96281bddf4a338e5 |
| scan_packages_for_cache_files.py | text/x-python | 5930 | MD5 4895e05b5d908a517f88371c76eb3bf4 |
| malicious.py | text/x-python | 38 | MD5 79284666664c1e25b49eda52ff70eccd |
| compile_and_poison.py | text/x-python | 1721 | MD5 f44bdf0f76a7f40bb248546ca91fbfe6 |
| MANIFEST.in | text/plain | 59 | MD5 e881e74dc0e133ecccc964f4591b81e0 |
| __init__.py | text/x-python | 0 | MD5 d41d8cd98f00b204e9800998ecf8427e |
| benign.py | text/x-python | 39 | MD5 021ff7b61b169c06212b627ccc3c8307 |
| python_37_314.py | text/x-python | 1241 | MD5 5131a3c9feec1fc0329ff3690b8a1fe1 |
| gator-core-__init__-3.11.13.pyc | application/octet-stream | 1276 | MD5 f5d2e26736b55da268f5dd48c106e73a |
| table-synthesis-GenerateTable-3.10.18.pyc | application/octet-stream | 6784 | MD5 b64fe185ced83aa8146a4c9d2d12a5eb |
| pyproject.toml | application/toml | 389 | MD5 8d090e615762f155a9b96eb24053b904 |
| README.md | text/markdown | 3530 | MD5 4466afbe8fa575ca11bf2aa699a20537 |
| README.md | text/markdown | 2866 | MD5 0e47fc900174635cab947e93335cb86e |
| readme.txt | text/plain | 4594 | MD5 c514ad69f947e12840623f0e17458485 |
| prepare.sh | application/x-shellscript | 983 | MD5 c2898eca22b71ed242944f8df904424f |
| pyproject.toml | application/toml | 390 | MD5 78901f870a1ae80963e9751dc22c9fce |
| README.md | text/markdown | 193 | MD5 e57800e4d7a7a2672c946994731d916e |
| pyproject.toml | application/toml | 195 | MD5 250b03649f41a107784886f04056b12b |
| pyproject.toml | application/toml | 201 | MD5 5b197d172f50d8141d9de4e1fb930845 |
Citation
Ohm, Marc; Pohl, Timo; Swierzy, Ben; Meier, Michael, 2026-01-30, Replication Code for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem", doi:10.60507/FK2/TNJHGT, V1.0
Additional Dataverse fields
| Id | 567 |
|---|---|
| Dataset Type | dataset |
| Internal Version Number | 277 |
| Latest Version Publishing State | RELEASED |
| Production Date | 2025-10-24 |
| Release Time | 2026-01-30T12:26:53Z |
| Create Time | 2026-01-19T13:09:57Z |
| Citation Date | 2026-01-30 |
| File Access Request | True |
Export metadata
Static metadata exports available for this published dataset version:
Complete Dataverse metadata
Expected crawler behaviour
Use a stable, truthful User-Agent with product/version and a working contact URL. Across all IP addresses and HTTP connections used by one crawler identity, allow no more than 5 requests in flight and wait at least 20 seconds between request starts. Crawl URLs listed in the catalog sitemap, including file pages and download URLs when they are published, use conditional requests, honor Retry-After, and apply exponential backoff after errors.
The welcome page may link to the interactive repository for human navigation. Automated clients must not treat that human link as a catalog crawl target.
Read the live machine-readable crawler policy before and during a crawl. Stop crawling when it reports CPU or memory utilization at or above 80% and 80% respectively.
