Page 116 - 《软件学报》2026年第7期
P. 116

胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究                                                     2801


                      2021/05/newly-discovered-bugs-in-vscode.html
                 [75]   Sangfor  Qianlimu  Security  Technology  Center.  The  mastermind  behind  four  supply  chain  poisoning  incidents  in  a  year.  2025  (in
                      Chinese). https://www.freebuf.com/articles/network/388355.html
                 [76]   Ernestas N. Dozens of DockerHub Linux images still contain a critical XZ Utils backdoor. 2025. https://cybernews.com/security/xz-utils-
                      backdoor-lurking-on-dockerhub/
                 [77]   Li  GL,  Wu  J,  Li  SH,  Yang  W,  Li  CL.  Multitentacle  federated  learning  over  software-defined  industrial  Internet  of  things  against
                      adaptive poisoning attacks. IEEE Trans. on Industrial Informatics, 2023, 19(2): 1260–1269. [doi: 10.1109/TII.2022.3173996]
                 [78]   Mao YW, Data D, Diggavi S, Tabuada P. Decentralized optimization resilient against local data poisoning attacks. IEEE Trans. on
                      Automatic Control, 2025, 70(1): 81–96. [doi: 10.1109/TAC.2024.3424693]
                 [79]   OWASP  Foundation.  CI/CD  security  cheat  sheet.  2024.  https://cheatsheetseries.owasp.org/cheatsheets/CI_CD_Security_Cheat_Sheet.
                      html
                 [80]   Krivelevich D, Gil O. OWASP top 10 CI/CD security risks. 2024. https://owasp.org/www-project-top-10-ci-cd-security-risks/
                 [81]   Sonar. Maintainer burnout is real. Almost 60% of maintainers have quit or considered quitting maintaining one of their projects. 2023.
                      https://www.sonarsource.com/blog/maintainer-burnout-is-real
                 [82]   Roth  E.  Open  source  developer  corrupts  widely-used  libraries,  affecting  tons  of  projects.  2022.  https://www.theverge.com/2022/1/9/
                      22874949/developer-corrupts-open-source-libraries-projects-affected
                 [83]   Amin Y. The human toll of log4j maintenance. 2021. https://dev.to/yawaramin/the-human-toll-of-log4j-maintenance-35ap
                 [84]   Gokkaya  B,  Aniello  L,  Halak  B.  Software  supply  chain:  Review  of  attacks,  risk  assessment  strategies  and  security  controls.  arXiv:
                      2305.14157, 2023.
                 [85]   Moore M, Kuppusamy TK, Cappos J. Artemis: Defanging software supply chain attacks in multi-repository update systems. In: Proc. of
                      the 39th Annual Computer Security Applications Conf. Austin: ACM, 2023. 83–97. [doi: 10.1145/3627106.3627129]
                 [86]   Gelb  Y.  New  technique  to  trick  developers  detected  in  an  open-source  supply  chain  attack.  2024.  https://checkmarx.com/blog/new-
                      technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/
                 [87]   Cao  A,  Dolan-Gavitt  B.  What  the  fork?  Finding  and  analyzing  malware  in  GitHub  forks.  In:  Proc.  of  the  2022  Workshop  on
                      Measurements, Attacks, and Defenses for the Web. 2022. [doi: 10.14722/madweb.2022.23001]
                 [88]   SnykVulnerabilityDatabase. Prototype Pollution. 2023. https://security.snyk.io/vuln/SNYK-JS-LODASH-6139239
                 [89]   Munoz  A.  The  octopus  scanner  malware:  Attacking  the  open  source  supply  chain.  2020. https://github.blog/security/vulnerability-
                      research/the-octopus-scanner-malware-attacking-the-open-source-supply-chain/
                 [90]   Lakshmanan R. Popular PyPI package ‘ctx’ and PHP library ‘phpass’ hijacked to steal AWS keys. 2022. https://thehackernews.com/
                      2022/05/pypi-package-ctx-and-php-library-phpass.html
                 [91]   Freebuf. VS Code ETHcode extension suffers supply chain attack: Two lines of malicious code injected via GitHub pull request. 2025
                      (in Chinese). https://www.freebuf.com/articles/development/438383.html
                 [92]   Zahan N, Zimmermann T, Godefroid P, Murphy B, Maddila C, Williams L. What are weak links in the npm supply chain? In: Proc. of
                      the 44th IEEE/ACM Int’l Conf. on Software Engineering: Software Engineering in Practice. Pittsburgh: IEEE, 2022. 331–340. [doi: 10.
                      1145/3510457.3513044]
                 [93]   Wu YL, Yu ZL, Wen M, Li Q, Zou DQ, Jin H. Understanding the threats of upstream vulnerabilities to downstream projects in the
                      maven ecosystem. In: Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering. Melbourne: IEEE, 2023. 1046–1058. [doi: 10.
                      1109/ICSE48619.2023.00095]
                 [94]   Mir AM, Keshani M, Proksch S. On the effect of transitivity and granularity on vulnerability propagation in the maven ecosystem. In:
                      Proc.  of  the  2023  IEEE  Int’l  Conf.  on  Software  Analysis,  Evolution  and  Reengineering.  IEEE,  2023.  201–211.  [doi: 10.1109/
                      SANER56733.2023.00028]
                 [95]   Mortenson S. A repository demonstrating how you can sneak malicious code into GitHub PRs. 2017. https://github.com/mortenson/pr-
                      sneaking
                 [96]   Goyal R, Ferreira G, Kästner C, Herbsleb J. Identifying unusual commits on GitHub. Journal of Software: Evolution and Process, 2018,
                      30(1): e1893. [doi: 10.1002/smr.1893]
                 [97]   Benedetti G, VerderameL, Merlo A. Automatic security assessment of GitHub actions workflows. In: Proc. of the 2022 ACM Workshop
                      on Software Supply Chain Offensive Research and Ecosystem Defenses. Los Angeles: ACM, 2022. 37–45.
                 [98]   Pathmanathan P, Chakraborty S, Liu XY, Liang YY, Huang FR. Is poisoning a real threat to LLM alignment? Maybe more so than you
                      think. arXiv:2406.12091, 2024.
                 [99]   Fu  TC,  Sharma  M,  Torr  P,  Cohen  SB,  Krueger  D,  Barez  F.  PoisonBench:  Assessing  large  language  model  vulnerability  to  data
   111   112   113   114   115   116   117   118   119   120   121