[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83011-en":3,"doc-seo-83011-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},83011,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Hidden Amplifiers Cross-Level Risk in Software Supply Chains","Modern software supply chains include hundreds of transitive dependencies, while current analysis tools operate either at the ecosystem level (dependency graphs) or at the code level (static analysis within packages). This separation produces two failures: false-positive CVE alerts for unreachable code, and blind spots for structurally critical micro-dependencies. A cross-level risk propagation framework unifies code-level risk metrics with ecosystem exposure via a single risk formula, revealing hidden amplifiers on 50 npm/PyPI packages.","Hidden Amplifiers: Cross-Level Risk in Software  \nSupply Chains  \nRakesh Podder  \nColorado State University Fort Collins, Colorado, USA [rakesh.podder@colostate.edu](rakesh.podder@colostate.edu)  \nRafael Fabian Gonzalez Arellano  \nColorado State University Fort Collins, Colorado, USA fabian.gonzalez [arellano@colostate.edu](arellano@colostate.edu)  \nIndrajit Ray  \nColorado State University Fort Collins, Colorado, USA [indrajit.ray@colostate.edu](indrajit.ray@colostate.edu)  \narXiv :2607 .05894v 1 [ cs . SE] 7 Jul 2026  \nAbstract—Modern software supply chains comprise hundreds of transitive dependencies, yet existing analysis tools operate at either the ecosystem level (dependency graphs) or the code level (static analysis within packages). This separation creates two failure modes. First, false-positive CVE alerts for unreachable code. Second, blind spots for structurally critical micro-dependencies. We introduce cross-level risk propagation, a framework that bridges code-level risk metrics with ecosystem-level dependency exposure through a unified risk formula. Preliminary evaluation on 50 packages across npm and PyPI reveals a class of hidden amplifiers—micro-dependencies with fewer than 50 methods but over 50,000 dependents—that carry outsized supply-chain risk invisible to all current Software Composition Analysis (SCA) tools. Without cross-level analysis, such packages can harbor exploitable code for years because no current tool considers both internal code structure and ecosystem position simultaneously. These results suggest that cross-level analysis opens a new design space for supply-chain security.  \nIndex Terms—software supply chain, dependency analysis, vulnerability prioritization, software composition analysis  \nI. INTRODUCTION  \nSoftware supply-chain attacks have surged in both frequency and impact [1], [2] . The SolarWinds compromise (2020) affected 18,000 organizations through a single build-system intrusion [3] . Log4Shell (2021) exposed a critical remote code execution vulnerability [4] in a logging library embedded in millions of Java applications. The event-stream incident (2018) demonstrated that a single malicious maintainer takeover of a micro-dependency can propagate to thousands of downstream projects within days [5] . In response, governments have elevated supply-chain security to a national priority—the U.S. Executive Order 14028 mandates Software Bills of Materials (SBOMs) and supply-chain risk assessment for federal software procurement [6] .  \nHowever, the scale of the problem amplifies these risks. npmalone hosts over 4 million packages, PyPI exceeds 763,000, and Maven Central surpasses 600,000—collectively serving billions of weekly downloads [7] . To manage this complexity, SCA tools such as Snyk [8], Dependabot [9], and npm audit have become the state of practice [10], [11] . These tools track known vulnerabilities at the package level, alerting developers when a dependency has a CVE. However, they treat each package as a black box—they cannot determine whether a vulnerability is reachable from the application’s  \ncode paths [12], nor can they assess the structural importance of a dependency in the ecosystem.  \nThis black-box limitation creates two concrete failure modes. First, false-positive overload. Many dependency-based CVE alerts target vulnerabilities in code that the consuming application never invokes, because SCA tools cannot distinguish reachable from unreachable functions. Developers learn to ignore alerts, burying genuine threats [13] . Second, hidden amplifier blind spots. Micro-dependencies such as ms (37 lines of JavaScript, over 829,000 dependents) carry enormous structural risk that no code-quality or SCA tool surfaces, because neither analyzes the relationship between internal code structure and ecosystem reach [12],[14],[15] . Zimmermann et al. [16] documented that individual npm maintainer accounts can impact up to 1 million packages, yet this risk remains invisible to c","cbCaikVY3uWiMu6B","https://ap.wps.com/l/cbCaikVY3uWiMu6B","pdf",301194,1,6,"English","en",105,"# Introduction\n## Problem scale and black-box limitations\n## Two failure modes\n## Paper contributions\n# Cross-Level Risk Framework\n## Core insight\n## Risk model","[{\"question\":\"What are the two main failure modes caused by separating ecosystem-level and code-level analysis?\",\"answer\":\"First, false-positive CVE alerts arise for unreachable code. Second, structurally critical micro-dependencies can be missed because current tools do not connect internal code structure with ecosystem reach.\"},{\"question\":\"What does the cross-level risk propagation framework do?\",\"answer\":\"It bridges code-level risk metrics with ecosystem-level dependency exposure by using a unified risk formula. This enables a single, comparable score for prioritizing methods and packages.\"},{\"question\":\"What are “hidden amplifiers” in this work?\",\"answer\":\"Hidden amplifiers are micro-dependencies with fewer than 50 methods but more than 50,000 dependents, carrying outsized supply-chain risk that current Software Composition Analysis tools do not surface.\"}]",1784184655,15,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"hidden-amplifiers-cross-level-risk-in-software-supply-chains","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/hidden-amplifiers-cross-level-risk-in-software-supply-chains/83011/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are the two main failure modes caused by separating ecosystem-level and code-level analysis?","Question",{"text":75,"@type":76},"First, false-positive CVE alerts arise for unreachable code. Second, structurally critical micro-dependencies can be missed because current tools do not connect internal code structure with ecosystem reach.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does the cross-level risk propagation framework do?",{"text":80,"@type":76},"It bridges code-level risk metrics with ecosystem-level dependency exposure by using a unified risk formula. This enables a single, comparable score for prioritizing methods and packages.",{"name":82,"@type":73,"acceptedAnswer":83},"What are “hidden amplifiers” in this work?",{"text":84,"@type":76},"Hidden amplifiers are micro-dependencies with fewer than 50 methods but more than 50,000 dependents, carrying outsized supply-chain risk that current Software Composition Analysis tools do not surface.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]