{"id":758822,"date":"2020-05-21T10:13:27","date_gmt":"2020-05-21T14:13:27","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=758822"},"modified":"2020-05-21T10:13:27","modified_gmt":"2020-05-21T14:13:27","slug":"a-review-of-open-source-software-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=758822","title":{"rendered":"A review of open-source software supply chain attacks"},"content":{"rendered":"<p>Here&#8217;s <a href=\"https:\/\/arxiv.org\/abs\/2005.09535\">a preprint paper<\/a> from<br \/>\nMarc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier looking at<br \/>\nattacks on language-specific repositories.  &#8220;<span>Recent years saw a<br \/>\nnumber of supply chain attacks that leverage the increasing use of open<br \/>\nsource during software development, which is facilitated by dependency<br \/>\nmanagers that automatically resolve, download and install hundreds of open<br \/>\nsource packages throughout the software life cycle. This paper presents a<br \/>\ndataset of 174 malicious software packages that were used in real-world<br \/>\nattacks on open source software supply chains, and which were distributed<br \/>\nvia the popular package repositories npm, PyPI, and RubyGems. Those<br \/>\npackages, dating from November 2015 to November 2019, were manually<br \/>\ncollected and analyzed. The paper also presents two general attack trees to<br \/>\nprovide a structured overview about techniques to inject malicious code<br \/>\ninto the dependency tree of downstream users, and to execute such code at<br \/>\ndifferent times and under different conditions.<\/span>&#8220;&#013;<br \/>\n&#013;<br \/>\nSource: LWN.net &#8211; <a href=\"https:\/\/lwn.net\/Articles\/821092\/rss\" target=\"_blank\" rel=\"noopener noreferrer\">A review of open-source software supply chain attacks<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here&#8217;s a preprint paper from Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier looking at attacks on language-specific repositories. &#8220;Recent years saw a number of supply chain attacks that leverage the increasing use of open source during software development, &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=758822\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[72],"tags":[75],"class_list":["post-758822","post","type-post","status-publish","format-standard","hentry","category-linux","tag-linux"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/758822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=758822"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/758822\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=758822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=758822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=758822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}