{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T05:02:51Z","timestamp":1784955771547,"version":"3.55.0"},"reference-count":31,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1109\/ecai69016.2026.11613644","type":"proceedings-article","created":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T19:09:37Z","timestamp":1784920177000},"page":"1-8","source":"Crossref","is-referenced-by-count":0,"title":["Software supply chain attacks in 2025\u20132026: comparative analysis of attack vectors, OSINT sources and design of a Machine Learning architecture for early warning"],"prefix":"10.1109","author":[{"given":"Adelaida","family":"St\u0103nciulescu","sequence":"first","affiliation":[{"name":"National University of Science and Technology Politehnica Bucharest","place":["Bucharest, Romania"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.19107\/CYBERCON.2023.25"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.19107\/CYBERCON.2024.11"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.19107\/ijisc.2025.02.03"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/sp46215.2023.10179304"},{"key":"ref5","article-title":"Popular DAEMON Tools Software Compromised","volume-title":"Kaspersky Securelist","year":"2026"},{"key":"ref6","article-title":"eScan Antivirus Supply Chain Compromise","year":"2026","journal-title":"Kaspersky Securelist"},{"key":"ref7","article-title":"Supply Chain Attacks Surge in March 2026","year":"2026","journal-title":"Zscaler Blog"},{"key":"ref8","volume-title":"Shai-Hulud V2 Poses Risk to NPM Supply Chain","year":"2025"},{"key":"ref9","volume-title":"The npm Threat Landscape: Attack Surface and Mitigations","year":"2026"},{"key":"ref10","volume-title":"\"Shai-Hulud\u201d Worm Compromises npm Ecosystem in Supply Chain Attack","year":"2025"},{"key":"ref11","article-title":"Analyzing TeamPCP Supply Chain Attacks: KICS and elementary-data","year":"2026","journal-title":"Trend Micro Research"},{"key":"ref12","volume-title":"Shai-Hulud 2.0: Guidance for Detecting, Investigating, and Defending Against the Supply Chain Attack","year":"2025"},{"key":"ref13","article-title":"Shai-Hulud 2.0: Inside The Second Coming, the Most Aggressive NPM Supply Chain Attack of 2025","volume-title":"Check Point Blog","year":"2025"},{"key":"ref14","article-title":"npm Supply Chain Attack Highlights New Risks","year":"2025","journal-title":"Sonatype Blog"},{"key":"ref15","volume-title":"2026 Software Supply Chain Security Report","year":"2026"},{"key":"ref16","volume-title":"Threat Landscape 2025","year":"2025"},{"key":"ref17","volume-title":"Cost of a Data Breach Report 2025","year":"2025"},{"key":"ref18","volume-title":"Data Breach Investigations Report 2025","year":"2025"},{"key":"ref19","article-title":"M-Trends 2026","year":"2026","journal-title":"Google Cloud Security"},{"key":"ref20","volume-title":"2026 State of the Software Supply Chain Report","year":"2026"},{"key":"ref21","article-title":"Widespread Supply Chain Compromise Impacting npm Ecosystem","year":"2025"},{"key":"ref22","article-title":"Mitigating the Axios npm Supply Chain Compromise","volume-title":"Microsoft Security Blog","year":"2026"},{"key":"ref23","article-title":"Mini Shai-Hulud: The Worm Returns and Goes Public","volume-title":"Akamai Blog","year":"2026"},{"key":"ref24","article-title":"Supply-chain Levels for Software Artifacts \u2014 Specification v1.0","year":"2024","journal-title":"slsa.dev"},{"key":"ref25","article-title":"Sigstore: A Standard for Signing, Verifying and Protecting Software","year":"2025","journal-title":"sigstore.dev"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510104"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3705304"},{"key":"ref29","article-title":"DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge Mapping","author":"Huang","year":"2024","journal-title":"USENIX Security"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3580336"},{"key":"ref31","article-title":"SocketAI: LLM-based Detection of Malicious npm Packages","author":"Zahan","year":"2025"}],"event":{"name":"2026 18th International Conference on Electronics, Computers and Artificial Intelligence (ECAI)","location":"Bucharest, Romania","start":{"date-parts":[[2026,7,2]]},"end":{"date-parts":[[2026,7,3]]}},"container-title":["2026 18th International Conference on Electronics, Computers and Artificial Intelligence (ECAI)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11613560\/11613162\/11613644.pdf?arnumber=11613644","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T04:39:53Z","timestamp":1784954393000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11613644\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":31,"URL":"https:\/\/doi.org\/10.1109\/ecai69016.2026.11613644","relation":{},"subject":[],"published":{"date-parts":[[2026,7]]}}}