Fetching the paper…
Reading the bibliography…
Modern software development frequently uses third-party packages, raising the concern of supply chain security attacks.
Building secure software: How to avoid security problems the right way, portable documents
John Viega and Gary R McGraw. 2001 · 2001
Earlier work this paper cites.
The influence of organizational structure on software quality. In 2008 ACM/IEEE 30th International Conference on Software Engineering . IEEE, 521–530
Nachiappan Nagappan, Brendan Murphy, and Victor Basili. 2008 · 2008
Earlier work this paper cites.
Does distributed development affect software quality? an empirical case study of windows vista. In 2009 IEEE 31st International Conference on Software Engineering . IEEE, 518–528
Bird, Christian, et al. 2009 · 2009
Earlier work this paper cites.
Secure open source collaboration: an empirical study of linus’ law. In Proceedings of the 16th ACM conference on Computer and communications security . 453–462
Andrew Meneely and Laurie Williams. 2009 · 2009
Earlier work this paper cites.
Don’t touch my code! Examining the effects of ownership on software quality. In Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering . 4–14
Bird, Christian, et al. 2011 · 2011
Earlier work this paper cites.
Weak signal identification with semantic web mining
Dirk Thorleuchter and Dirk Van den Poel. 2013 · 2013
Earlier work this paper cites.
“The Untold Story of NotPetya, the Most Devastating Cyberattack in History
Mike Mcquade. 2018 · 2017
Earlier work this paper cites.
Backdoored Python Library Caught Stealing SSH Credentials
Catalin Cimpanu. 2018 · 2018
Earlier work this paper cites.
Core contributor to the conventional-changelog ecosystem had their npm credentials compromised
Benjamin E. Coe. 2018 · 2018
Earlier work this paper cites.
Npm Attackers Sneak a Backdoor into Node.js Deployments through Dependencies
Lucian Constantin. 2018 · 2018
Earlier work this paper cites.
Postmortem for Malicious Packages Published on July 12th, 2018
Eslint. 2018 · 2018
Earlier work this paper cites.
Gathering weak npm credentials
Ckobopoaa Hnknta. 2018 · 2018
Earlier work this paper cites.
Compromised npm Package: event-stream
Thomas Hunter II. 2018 · 2018
Earlier work this paper cites.
CCleaner Attack Timeline—Here’s How Hackers Infected 2.3 Million PCs
Swati Khandelwal. 2018 · 2018
Earlier work this paper cites.
eslint-scope attack
Henry Zhu. 2018 · 2018
Cited alongside, same era.
Detecting suspicious package updates. In 2019 IEEE/ACM 41st International Conference on Software Engineering: New Ideas and Emerging Results (ICSE-NIER) . IEEE, 13–16
Garrett, Kalil, et al. 2019 · 2019
Cited alongside, same era.
10 npm Security Best Practices
Liran Tal and Juan Picado. 2019 · 2019
Cited alongside, same era.
The Adverline Breach and the Emerging Risk of Using Third-Party Vendors
The Integrity360 Team. 2019 · 2019
Cited alongside, same era.
Security issues in language-based sofware ecosystems
Ruturaj K Vaidya, Lorenzo De Carli, Drew Davidson, and Vaibhav Rastogi. 2019 · 2019
Cited alongside, same era.
Bash Uploader Security Update
Codecov. 2021 · 2021
Closest in time.
The Hijacking of Perl.com
Brian d foy. 2021 · 2021
Closest in time.
SolarWinds Attack Cost Impacted Companies an Average of $12 Million
Cezarina Dinu. 2021 · 2021
Closest in time.
Security holding Package
Natasha Dorfman. 2021 · 2021
Closest in time.
Containing malicious package updates in npm with a lightweight permission system. In 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE) . IEEE, 1334–1346
Gabriel Ferreira, Limin Jia, Joshua Sunshine, and Christian Kästner. 2021 · 2021
Closest in time.
Lessons Learned From the SolarWinds Supply Chain Hack
Jack M. Germain. 2021 · 2021
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Zimmermann, Markus, et al. 2019 · 2019
Cited alongside, same era.
SolarWinds attack explained: And why it was so hard to detect
Lucian Constantin. 2020 · 2020
Cited alongside, same era.
Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages
Duan, Ruian, et al. 2020 · 2020
Cited alongside, same era.
Secure at every step: What is software supply chain security and why does it matter?
Maya Kaczorowski. 2020 · 2020
Cited alongside, same era.
The State of Open Source Security 2020
Alyssa Miller and Sharone Zitzman. 2020 · 2020
Cited alongside, same era.
Backstabber’s knife collection: A review of open source software supply chain attacks. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment . Springer, 23–43
Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. 2020 · 2020
Cited alongside, same era.
2020 STATE OF THE SOFTWARE SUPPLY CHAIN REPORT
Sonatype. 2020 · 2020
Cited alongside, same era.
Anomalicious: Automated Detection of Anomalous and Potentially Malicious Commits on GitHub. In 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) . IEEE, 258–267
Gonzalez, Danielle, et al. 2021 · 2021
Closest in time.
SolarWinds Orion Security Breach: A Shift In The Software Supply Chain Paradigm
Anton Hoffman. 2021 · 2021
Closest in time.
Embedded Malware in NPM: Coa, Rc, Ua-parser
G. Polasani and S. Rubin. 2021 · 2021
Closest in time.
Dependency-confusion
Ax Sharma. 2021 · 2021
Closest in time.
2021 STATE OF THE SOFTWARE SUPPLY CHAIN REPORT
Sonatype. 2021 · 2021
Closest in time.
Snyk uncovers malicious code activities in open source supply chain security on the npm registry
Liran Tal. 2021 · 2021
Closest in time.
Top-100 npm package maintainers now require 2FA
Myles Borins. 2022 · 2022
Closest in time.