SoK: Taxonomy of Attacks on Open-Source Software Supply Chains
Piergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier Barais
Abstract
The widespread dependency on open-source software makes it a fruitful target for malicious actors, as demonstrated by recurring attacks. The complexity of today’s open-source supply chains results in a significant attack surface, giving attackers numerous opportunities to reach the goal of injecting malicious code into open-source artifacts that is then downloaded and executed by victims.This work proposes a general taxonomy for attacks on open-source supply chains, independent of specific programming languages or ecosystems, and covering all supply chain stages from code contributions to package distribution. Taking the form of an attack tree, it covers 107 unique vectors, linked to 94 real-world incidents, and mapped to 33 mitigating safeguards.User surveys conducted with 17 domain experts and 134 software developers positively validated the correctness, comprehensiveness and comprehensibility of the taxonomy, as well as its suitability for various use-cases. Survey participants also assessed the utility and costs of the identified safeguards, and whether they are used.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8acc8751-e7db-4edb-a75f-212f5cf34964Cited by top-tier papers56
- SoK: Security and Privacy of Blockchain InteroperabilityAndré Augusto, Rafael Belchior, Miguel Correia, André Vasconcelos et al.S&P 2024 · 90 citations
- SoK: What don't we know? Understanding Security Vulnerabilities in SNARKsStefanos Chaliasos, Jens Ernstberger, David Theodore, David Wong et al.USENIX Security 2024 · 32 citations
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang et al.ASE 2023 · 31 citations
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- "We Feel Like We're Winging It: " A Study on Navigating Open-Source Dependency AbandonmentCourtney Miller, Christian Kästner, Bogdan VasilescuFSE 2023 · 19 citations
Builds on12
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola et al.USENIX Security 2019 · 98 citations
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 91 citations
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 78 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
Related papers
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li et al.ISSTA 2025 · 3 citations
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl et al.ICSE 2025 · 1 citation
- V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification TechniquesSeunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo OhUSENIX Security 2023
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines et al.ICSE 2026 · 5 citations
- "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply ChainDominik Wermke, Jan H. Klemmer, Noah Wöhler, Juliane Schmüser et al.S&P 2023
