Page 116 - 《软件学报》2026年第7期
P. 116
胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究 2801
2021/05/newly-discovered-bugs-in-vscode.html
[75] Sangfor Qianlimu Security Technology Center. The mastermind behind four supply chain poisoning incidents in a year. 2025 (in
Chinese). https://www.freebuf.com/articles/network/388355.html
[76] Ernestas N. Dozens of DockerHub Linux images still contain a critical XZ Utils backdoor. 2025. https://cybernews.com/security/xz-utils-
backdoor-lurking-on-dockerhub/
[77] Li GL, Wu J, Li SH, Yang W, Li CL. Multitentacle federated learning over software-defined industrial Internet of things against
adaptive poisoning attacks. IEEE Trans. on Industrial Informatics, 2023, 19(2): 1260–1269. [doi: 10.1109/TII.2022.3173996]
[78] Mao YW, Data D, Diggavi S, Tabuada P. Decentralized optimization resilient against local data poisoning attacks. IEEE Trans. on
Automatic Control, 2025, 70(1): 81–96. [doi: 10.1109/TAC.2024.3424693]
[79] OWASP Foundation. CI/CD security cheat sheet. 2024. https://cheatsheetseries.owasp.org/cheatsheets/CI_CD_Security_Cheat_Sheet.
html
[80] Krivelevich D, Gil O. OWASP top 10 CI/CD security risks. 2024. https://owasp.org/www-project-top-10-ci-cd-security-risks/
[81] Sonar. Maintainer burnout is real. Almost 60% of maintainers have quit or considered quitting maintaining one of their projects. 2023.
https://www.sonarsource.com/blog/maintainer-burnout-is-real
[82] Roth E. Open source developer corrupts widely-used libraries, affecting tons of projects. 2022. https://www.theverge.com/2022/1/9/
22874949/developer-corrupts-open-source-libraries-projects-affected
[83] Amin Y. The human toll of log4j maintenance. 2021. https://dev.to/yawaramin/the-human-toll-of-log4j-maintenance-35ap
[84] Gokkaya B, Aniello L, Halak B. Software supply chain: Review of attacks, risk assessment strategies and security controls. arXiv:
2305.14157, 2023.
[85] Moore M, Kuppusamy TK, Cappos J. Artemis: Defanging software supply chain attacks in multi-repository update systems. In: Proc. of
the 39th Annual Computer Security Applications Conf. Austin: ACM, 2023. 83–97. [doi: 10.1145/3627106.3627129]
[86] Gelb Y. New technique to trick developers detected in an open-source supply chain attack. 2024. https://checkmarx.com/blog/new-
technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/
[87] Cao A, Dolan-Gavitt B. What the fork? Finding and analyzing malware in GitHub forks. In: Proc. of the 2022 Workshop on
Measurements, Attacks, and Defenses for the Web. 2022. [doi: 10.14722/madweb.2022.23001]
[88] SnykVulnerabilityDatabase. Prototype Pollution. 2023. https://security.snyk.io/vuln/SNYK-JS-LODASH-6139239
[89] Munoz A. The octopus scanner malware: Attacking the open source supply chain. 2020. https://github.blog/security/vulnerability-
research/the-octopus-scanner-malware-attacking-the-open-source-supply-chain/
[90] Lakshmanan R. Popular PyPI package ‘ctx’ and PHP library ‘phpass’ hijacked to steal AWS keys. 2022. https://thehackernews.com/
2022/05/pypi-package-ctx-and-php-library-phpass.html
[91] Freebuf. VS Code ETHcode extension suffers supply chain attack: Two lines of malicious code injected via GitHub pull request. 2025
(in Chinese). https://www.freebuf.com/articles/development/438383.html
[92] Zahan N, Zimmermann T, Godefroid P, Murphy B, Maddila C, Williams L. What are weak links in the npm supply chain? In: Proc. of
the 44th IEEE/ACM Int’l Conf. on Software Engineering: Software Engineering in Practice. Pittsburgh: IEEE, 2022. 331–340. [doi: 10.
1145/3510457.3513044]
[93] Wu YL, Yu ZL, Wen M, Li Q, Zou DQ, Jin H. Understanding the threats of upstream vulnerabilities to downstream projects in the
maven ecosystem. In: Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering. Melbourne: IEEE, 2023. 1046–1058. [doi: 10.
1109/ICSE48619.2023.00095]
[94] Mir AM, Keshani M, Proksch S. On the effect of transitivity and granularity on vulnerability propagation in the maven ecosystem. In:
Proc. of the 2023 IEEE Int’l Conf. on Software Analysis, Evolution and Reengineering. IEEE, 2023. 201–211. [doi: 10.1109/
SANER56733.2023.00028]
[95] Mortenson S. A repository demonstrating how you can sneak malicious code into GitHub PRs. 2017. https://github.com/mortenson/pr-
sneaking
[96] Goyal R, Ferreira G, Kästner C, Herbsleb J. Identifying unusual commits on GitHub. Journal of Software: Evolution and Process, 2018,
30(1): e1893. [doi: 10.1002/smr.1893]
[97] Benedetti G, VerderameL, Merlo A. Automatic security assessment of GitHub actions workflows. In: Proc. of the 2022 ACM Workshop
on Software Supply Chain Offensive Research and Ecosystem Defenses. Los Angeles: ACM, 2022. 37–45.
[98] Pathmanathan P, Chakraborty S, Liu XY, Liang YY, Huang FR. Is poisoning a real threat to LLM alignment? Maybe more so than you
think. arXiv:2406.12091, 2024.
[99] Fu TC, Sharma M, Torr P, Cohen SB, Krueger D, Barez F. PoisonBench: Assessing large language model vulnerability to data

