Page 118 - 《软件学报》2026年第7期
P. 118

胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究                                                     2803


                 [123]   Dong T, Xue MH, Chen GX, Holland R, Meng Y, Li SF, Liu Z, Zhu HJ. The philosopher’s stone: Trojaning plugins of large language
                      models. In: Proc. of the 32nd Annual Network and Distributed System Security Symp. San Diego: The Internet Society, 2025.
                 [124]   Cybersecurity  and  Infrastructure  Security  Agency.  Advanced  persistent  threat  compromise  of  government  agencies,  critical
                      infrastructure, and private sector organizations. 2021. https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a
                 [125]   Lakshmanan R. Critical open VSX registry flaw exposes millions of developers to supply chain attacks. 2025. https://thehackernews.com/
                      2025/06/critical-open-vsx-registry-flaw-exposes.html
                 [126]   GitHub. Oneinstack issue #487. 2023 (in Chinese). https://github.com/oneinstack/oneinstack/issues/487
                 [127]   ThreatLabz.  Anatomy  of  an  ongoing  drive-by-download  campaign.  2013. https://www.zscaler.com/blogs/security-research/anatomy-
                      ongoing-drive-download-campaign
                 [128]   Mandiant.  North  Korea  leverages  SaaS  provider  in  a  targeted  supply  chain  attack.  2023. https://cloud.google.com/blog/topics/threat-
                      intelligence/north-korea-supply-chain
                 [129]   Zanki  K.  Malware  leveraging  public  infrastructure  like  GitHub  on  the  rise.  2023. https://www.reversinglabs.com/blog/malware-
                      leveraging-public-infrastructure-like-github-on-the-rise
                 [130]   Ranjan I, Agnihotri RB. Ambiguity in cloud security with malware-injection attack. In: Proc. of the 3rd Int’l Conf. on Electronics,
                      Communication and Aerospace Technology. Coimbatore: IEEE, 2019. 306–310. [doi: 10.1109/ICECA.2019.8821844]
                 [131]   Damjanović DZ. Malicious code in the cloud. Vojnotehnički Glasnik, 2022, 70(3): 734–755. [doi: 10.5937/vojtehg70-37168]
                 [132]   Rao BVS, Sharma V, Rathore N, Prasad D, Anandaram H, Soni G. A secure framework to prevent three-tier cloud architecture from
                      malicious malware injection attacks. Int’l Journal of Cloud Applications and Computing, 2023, 13(1): 1–22. [doi: 10.4018/ijcac.317220]
                 [133]   Alibaba  Cloud.  PyPi  supply  chain  poisoning  series  incidents:  Discord  assists  hacker  attacks.  2021  (in  Chinese).  https://developer.
                      aliyun.com/article/787142/
                 [134]   Zanki K. Update: IconBurst npm software supply chain attack grabs data from Apps and websites. 2025. https://www.reversinglabs.
                      com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
                 [135]   Snyk  Research  Team.  Malicious  package  in  @yandex-travel/ui.  2025. https://security.snyk.io/vuln/SNYK-JS-YANDEXTRAVELUI-
                      3319915
                 [136]   National Institute of Standards and Technology. CVE-2023-45311 detail. 2025. https://nvd.nist.gov/vuln/detail/CVE-2023-45311
                 [137]   OneinStack.  Malicious  code  found  in  domestic  mirrors  of  mirrors.oneinstack.com.  2025  (in  Chinese).  https://github.com/oneinstack/
                      oneinstack/issues/511
                 [138]   Antiy Labs. Analysis of espionage trojan propagation attacks via GitHub. 2024 (in Chinese). https://www.freebuf.com/articles/network/
                      395369.html
                 [139]   Qi'anxin CodeGuard. Software supply chain poisoning—Analysis of malicious NPM packages (Part 2). 2024 (in Chinese). https://www.
                      freebuf.com/articles/database/395549.html
                 [140]   Xmirror  Security  Intelligence  Center.  Malicious  NPM  Package  (fix-this)  launches  reverse  shell  remote  control  poisoning.  2025  (in
                      Chinese). https://www.xmirror.cn/particulars?id=3225&type=dt
                 [141]   Fiedler M. Malware distribution and domain abuse. 2025. https://blog.pypi.org/posts/2024-04-10-domain-abuse/
                 [142]   Xmirror Security Monthly Report. Release of open-source supply chain poisoning monthly report April 2024. 2024 (in Chinese). https://
                      opensca.xmirror.cn/resources/particulars?id=143
                 [143]   Xmirror Security Intelligence Center (Supply Chain Poisoning Warning). Malicious Python package disguised as HTTP component
                      launches CStealer espionage backdoor attack. 2024 (in Chinese). https://www.freebuf.com/news/400487.html
                 [144]   Huorong  Security.  GitHub  open-source  projects  poisoned:  Backdoor  viruses  spread  along  with  development  processes.  2025  (in
                      Chinese). https://huorong.cn/document/tech/vir_report/1802/
                 [145]   Sonatype. State of the software supply chain. 2025. https://www.sonatype.com/state-of-the-software-supply-chain/Introduction
                 [146]   Prates L, Pereira R. DevSecOps practices and tools. Int’l Journal of Information Security, 2025, 24(1): 11. [doi: 10.1007/s10207-024-
                      00914-z]
                 [147]   Froh FN, Gobbi MF, Kinder J. Differential static analysis for detecting malicious updates to open source packages. In: Proc. of the 2023
                      Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses. Copenhagen: ACM, 2023. 41–49. [doi: 10.1145/
                      3605770.3625211]
                 [148]   Zheng XY, Wei C, Wang SN, Zhao YJ, Gao PM, Zhang YC, Wang KL, Wang HY. Towards robust detection of open source software
                      supply  chain  poisoning  attacks  in  industry  environments.  In:  Proc.  of  the  39th  IEEE/ACM  Int’l  Conf.  on  Automated  Software
                      Engineering. Sacramento: ACM, 2024. 1990–2001. [doi: 10.1145/3691620.3695262]
                 [149]   Shariffdeen R, Hassanshahi B, Mirchev M, El Husseini A, Roychoudhury A. Detecting Python malware in the software supply chain
   113   114   115   116   117   118   119   120   121   122   123