Mallesh M. Pai

43 papers A* 9A 2B 4Journal 27Unranked 1
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Nir Lavee, Noam Nisan, Mallesh M. Pai, Max Resnick
2025 B conf
AFT
Fei Wu, Danning Sui, Thomas Thiery, Mallesh M. Pai
2025 J jnl
CoRR
Fei Wu, Danning Sui, Thomas Thiery, Mallesh M. Pai
2024 J jnl
CoRR
Tarun Chitra, Kshitij Kulkarni, Mallesh M. Pai, Theo Diamandis
2024 J jnl
CoRR
Mallesh M. Pai, Max Resnick
2024 J jnl
CoRR
Tarun Chitra, Mallesh M. Pai
2024 B conf
AFT
Michael Neuder, Mallesh M. Pai, Max Resnick
2024 J jnl
CoRR
Michael Neuder, Mallesh M. Pai, Max Resnick
2024 J jnl
Optim. Lett.
Raul Garcia, Seyedmohammadhossein Hosseinian, Mallesh M. Pai, Andrew J. Schaefer
2024 conf
FC Workshops
Mallesh M. Pai, Max Resnick
2023 B conf
AFT
Elijah Fox, Mallesh M. Pai, Max Resnick
2023 J jnl
CoRR
Mallesh M. Pai, Max Resnick, Elijah Fox
2023 A* conf
EC
Mallesh M. Pai, Philipp Strack
2023 B conf
AFT
Tivas Gupta, Mallesh M. Pai, Max Resnick
2023 A* conf
EC
Yi-Chun Chen, Manuel Mueller-Frank, Mallesh M. Pai
2022 J jnl
J. Econ. Theory
Yi-Chun Chen, Manuel Mueller-Frank, Mallesh M. Pai
2022 A* conf
NeurIPS
Daniel Lee, Georgy Noarov, Mallesh M. Pai, Aaron Roth
2022 A conf
ITCS
Varun Gupta, Christopher Jung, Georgy Noarov, Mallesh M. Pai, Aaron Roth
2021 J jnl
Mark. Sci.
Karsten Hansen, Kanishka Misra, Mallesh M. Pai
2021 A* conf
COLT
Christopher Jung, Changhwa Lee, Mallesh M. Pai, Aaron Roth, Rakesh Vohra
2021 J jnl
CoRR
Georgy Noarov, Mallesh M. Pai, Aaron Roth
2021 J jnl
CoRR
Varun Gupta, Christopher Jung, Georgy Noarov, Mallesh M. Pai, Aaron Roth
2021 J jnl
CoRR
Yi-Chun Chen, Manuel Mueller-Frank, Mallesh M. Pai
2020 A* conf
EC
Christopher Jung, Sampath Kannan, Changhwa Lee, Mallesh M. Pai, Aaron Roth, Rakesh Vohra
2020 J jnl
CoRR
Christopher Jung, Sampath Kannan, Changhwa Lee, Mallesh M. Pai, Aaron Roth, Rakesh Vohra
2020 J jnl
CoRR
Christopher Jung, Changhwa Lee, Mallesh M. Pai, Aaron Roth, Rakesh Vohra
2019 J jnl
CoRR
Jose Luis Montiel Olea, Pietro Ortoleva, Mallesh M. Pai, Andrea Prat
2017 J jnl
ACM Trans. Economics and Comput.
Mallesh M. Pai, Aaron Roth, Jonathan R. Ullman
2017 A* conf
EC
Sampath Kannan, Michael J. Kearns, Jamie Morgenstern, Mallesh M. Pai, Aaron Roth, Rakesh V. Vohra, Zhiwei Steven Wu
2017 J jnl
CoRR
Sampath Kannan, Michael J. Kearns, Jamie Morgenstern, Mallesh M. Pai, Aaron Roth, Rakesh V. Vohra, Zhiwei Steven Wu
2016 A* conf
EC
Rachel Cummings, Katrina Ligett, Mallesh M. Pai, Aaron Roth
2015 J jnl
CoRR
Michael J. Kearns, Mallesh M. Pai, Ryan M. Rogers, Aaron Roth, Jonathan R. Ullman
2015 J jnl
CoRR
Rachel Cummings, Katrina Ligett, Mallesh M. Pai, Aaron Roth
2014 J jnl
CoRR
Mallesh M. Pai, Aaron Roth, Jonathan R. Ullman
2014 J jnl
J. Econ. Theory
Nabil I. Al-Najjar, Mallesh M. Pai
2014 A conf
ITCS
Michael J. Kearns, Mallesh M. Pai, Aaron Roth, Jonathan R. Ullman
2014 J jnl
J. Econ. Theory
Mallesh M. Pai, Rakesh Vohra
2013 A* conf
SODA
Rahul Deb, Mallesh M. Pai
2013 J jnl
Math. Oper. Res.
Mallesh M. Pai, Rakesh Vohra
2013 J jnl
CoRR
Mallesh M. Pai, Aaron Roth
2013 J jnl
SIGecom Exch.
Mallesh M. Pai, Aaron Roth
2010 A* conf
EC
Jon Feldman, Vahab S. Mirrokni, S. Muthukrishnan, Mallesh M. Pai
2010 J jnl
SIGecom Exch.
Mallesh M. Pai
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));