{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T00:08:32Z","timestamp":1755994112537,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,19]],"date-time":"2023-11-19T00:00:00Z","timestamp":1700352000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,19]]},"DOI":"10.1145\/3689944.3696166","type":"proceedings-article","created":{"date-parts":[[2024,11,19]],"date-time":"2024-11-19T18:24:02Z","timestamp":1732040642000},"page":"33-42","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["GoSurf: Identifying Software Supply Chain Attack Vectors in Go"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7557-4973","authenticated-orcid":false,"given":"Carmine","family":"Cesarano","sequence":"first","affiliation":[{"name":"Universit\u00e0 degli Studi di Napoli Federico II, Naples, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6519-625X","authenticated-orcid":false,"given":"Vivi","family":"Andersson","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1084-4824","authenticated-orcid":false,"given":"Roberto","family":"Natella","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi di Napoli Federico II, Naples, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3505-3383","authenticated-orcid":false,"given":"Martin","family":"Monperrus","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,19]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Hijackable Go Module Repositories. https:\/\/vulncheck.com\/blog\/go-repojacking. Online","author":"Jacob Baines VulnCheck","year":"2024","unstructured":"VulnCheck Jacob Baines. 2023. Hijackable Go Module Repositories. https:\/\/vulncheck.com\/blog\/go-repojacking. Online; accessed 9 June 2024."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3057720"},{"key":"e_1_3_2_1_3_1","unstructured":"Synopsys Cybersecurity Research Center (CyRC). 2024. Open Source Security and Risk Analysis (OSSRA) Report."},{"key":"e_1_3_2_1_4_1","unstructured":"Go Ethereum. 2024. go-ethereum - Official Go implementation of the Ethereum protocol. https:\/\/geth.ethereum.org\/"},{"key":"e_1_3_2_1_5_1","volume-title":"https:\/\/github.com\/IceWhaleTech\/CasaOS\/blob\/main\/main.go. Online","author":"OS.","year":"2024","unstructured":"github user. 2024. CasaOS. https:\/\/github.com\/IceWhaleTech\/CasaOS\/blob\/main\/main.go. Online; accessed 9 June 2024."},{"volume-title":"https:\/\/github.com\/hashicorp\/terraform\/blob\/8e4d4663fe37bbae3c0dc1c0bb20b6bcb17b637c\/Makefile#L5. Online","year":"2024","key":"e_1_3_2_1_6_1","unstructured":"Hashicorp. 2024. Terraform. https:\/\/github.com\/hashicorp\/terraform\/blob\/8e4d4663fe37bbae3c0dc1c0bb20b6bcb17b637c\/Makefile#L5. Online; accessed 9 June 2024."},{"volume-title":"https:\/\/github.com\/hashicorp\/vault\/blob\/f7c16796ed2482b5a595b5d89673e4ec5ff8e7fe\/Makefile#L162. Online","year":"2024","key":"e_1_3_2_1_7_1","unstructured":"Hashicorp. 2024. Vault. https:\/\/github.com\/hashicorp\/vault\/blob\/f7c16796ed2482b5a595b5d89673e4ec5ff8e7fe\/Makefile#L162. Online; accessed 9 June 2024."},{"key":"e_1_3_2_1_8_1","volume-title":"Finding Evil Go Packages. https:\/\/michenriksen.com\/archive\/blog\/finding-evil-go-packages\/. Online","author":"Henriksen Michael","year":"2024","unstructured":"Michael Henriksen. 2021. Finding Evil Go Packages. https:\/\/michenriksen.com\/archive\/blog\/finding-evil-go-packages\/. Online; accessed 22 June 2024."},{"volume-title":"istio. https:\/\/github.com\/istio\/istio\/blob\/8d200be6d52283c806dfce37ae2241efa915f8fd\/Makefile.core.mk#L313. Online","year":"2024","key":"e_1_3_2_1_9_1","unstructured":"Istio. 2024. istio. https:\/\/github.com\/istio\/istio\/blob\/8d200be6d52283c806dfce37ae2241efa915f8fd\/Makefile.core.mk#L313. Online; accessed 9 June 2024."},{"volume-title":"CHANGELOG v1.29. https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/CHANGELOG\/CHANGELOG-1.29.md. Online","year":"2024","key":"e_1_3_2_1_10_1","unstructured":"Kubernetes. 2024. CHANGELOG v1.29. https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/CHANGELOG\/CHANGELOG-1.29.md. Online; accessed 21 June 2024."},{"key":"e_1_3_2_1_11_1","unstructured":"Kubernetes. 2024. Kubernetes - Production-Grade Container Orchestration. https:\/\/kubernetes.io\/"},{"key":"e_1_3_2_1_12_1","volume-title":"Update: IconBurst npm software supply chain attack grabs data from apps and websites. https:\/\/www.reversinglabs.com\/blog\/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites Online","author":"Labs Reversing","year":"2022","unstructured":"Reversing Labs. 2022. Update: IconBurst npm software supply chain attack grabs data from apps and websites. https:\/\/www.reversinglabs.com\/blog\/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites Online; accessed 9 June 2024."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179304"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605770.3625212"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00063"},{"key":"e_1_3_2_1_16_1","volume-title":"DIMVA 2020, Lisbon, Portugal, June 24--26, 2020, Proceedings 17","author":"Ohm Marc","year":"2020","unstructured":"Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. 2020. Backstabber's knife collection: A review of open source software supply chain attacks. In Detection of Intrusions and Malware, and Vulnerability Assessment: 17th International Conference, DIMVA 2020, Lisbon, Portugal, June 24--26, 2020, Proceedings 17. Springer, 23--43."},{"key":"e_1_3_2_1_17_1","volume-title":"capslock package. https:\/\/pkg.go.dev\/github.com\/google\/capslock. Online","author":"Packages Go","year":"2024","unstructured":"Go Packages. 2024. capslock package. https:\/\/pkg.go.dev\/github.com\/google\/capslock. Online; accessed 10 June 2024."},{"key":"e_1_3_2_1_18_1","volume-title":"go vet package. https:\/\/pkg.go.dev\/cmd\/vet. Online","author":"Packages Go","year":"2024","unstructured":"Go Packages. 2024. go vet package. https:\/\/pkg.go.dev\/cmd\/vet. Online; accessed 20 June 2024."},{"key":"e_1_3_2_1_19_1","volume-title":"gosec package. https:\/\/pkg.go.dev\/github.com\/securego\/gosec\/v2. Online","author":"Packages Go","year":"2024","unstructured":"Go Packages. 2024. gosec package. https:\/\/pkg.go.dev\/github.com\/securego\/gosec\/v2. Online; accessed 20 June 2024."},{"key":"e_1_3_2_1_20_1","volume-title":"2024 d. govulncheck. https:\/\/pkg.go.dev\/golang.org\/x\/vuln\/cmd\/govulncheck. Online","author":"Packages Go","year":"2024","unstructured":"Go Packages. 2024 d. govulncheck. https:\/\/pkg.go.dev\/golang.org\/x\/vuln\/cmd\/govulncheck. Online; accessed 20 June 2024; Language version go1.22."},{"key":"e_1_3_2_1_21_1","volume-title":"2024 e. m-mizutani\/goast. https:\/\/pkg.go.dev\/github.com\/m-mizutani\/goast. Online","author":"Packages Go","year":"2024","unstructured":"Go Packages. 2024 e. m-mizutani\/goast. https:\/\/pkg.go.dev\/github.com\/m-mizutani\/goast. Online; accessed 20 June 2024."},{"key":"e_1_3_2_1_22_1","volume-title":"Go at Google: Language Design in the Service of Software Engineering. https:\/\/go.dev\/talks\/2012\/splash.article. Online","author":"Pike Rob","year":"2024","unstructured":"Rob Pike. 2012. Go at Google: Language Design in the Service of Software Engineering. https:\/\/go.dev\/talks\/2012\/splash.article. Online; accessed 27 May 2024."},{"key":"e_1_3_2_1_23_1","volume-title":"Generating code - The Go Programming Language. https:\/\/go.dev\/blog\/generate. Online","author":"Pike Rob","year":"2024","unstructured":"Rob Pike. 2014. Generating code - The Go Programming Language. https:\/\/go.dev\/blog\/generate. Online; accessed 29 May 2024."},{"key":"e_1_3_2_1_24_1","volume-title":"The Design of the Go Assembler. https:\/\/go.dev\/talks\/2016\/asm Presented at Gophercon. Online","author":"Pike Rob","year":"2024","unstructured":"Rob Pike. 2016. The Design of the Go Assembler. https:\/\/go.dev\/talks\/2016\/asm Presented at Gophercon. Online; accessed 12 June 2024."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3554732"},{"volume-title":"https:\/\/pkg.go.dev\/github.com\/sonatype-nexus-community\/nancy. Online","year":"2024","key":"e_1_3_2_1_26_1","unstructured":"Sonatype. 2024. Nancy. https:\/\/pkg.go.dev\/github.com\/sonatype-nexus-community\/nancy. Online; accessed 20 June 2024; Language version go1.22."},{"volume-title":"PyPI crypto-stealer targets Windows users, revives malware campaign. https:\/\/www.sonatype.com\/blog\/pypi-crypto-stealer-targets-windows-users-revives-malware-campaign. Online","year":"2024","key":"e_1_3_2_1_27_1","unstructured":"Sonatype. 2024. PyPI crypto-stealer targets Windows users, revives malware campaign. https:\/\/www.sonatype.com\/blog\/pypi-crypto-stealer-targets-windows-users-revives-malware-campaign. Online; accessed 9 June 2024."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW59333.2023.00036"},{"key":"e_1_3_2_1_29_1","volume-title":"Annual Developer Survey. https:\/\/survey.stackoverflow.co\/. Online","author":"Overflow Stack","year":"2024","unstructured":"Stack Overflow. 2023. Annual Developer Survey. https:\/\/survey.stackoverflow.co\/. Online; accessed 26 June 2024."},{"key":"e_1_3_2_1_30_1","volume-title":"Go Doc - Effective Go. https:\/\/go.dev\/doc\/effective_go. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024. Go Doc - Effective Go. https:\/\/go.dev\/doc\/effective_go. Online; accessed 2 July 2024."},{"key":"e_1_3_2_1_31_1","volume-title":"Go Modules Reference. https:\/\/go.dev\/ref\/mod. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024. Go Modules Reference. https:\/\/go.dev\/ref\/mod. Online; accessed 24 May 2024."},{"key":"e_1_3_2_1_32_1","volume-title":"The Go Programming Language Specification. https:\/\/go.dev\/ref. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024. The Go Programming Language Specification. https:\/\/go.dev\/ref. Online; accessed 10 June 2024; Language version go1.22."},{"key":"e_1_3_2_1_33_1","volume-title":"2024 d. Package names. https:\/\/go.dev\/blog\/package-names. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024 d. Package names. https:\/\/go.dev\/blog\/package-names. Online; accessed 28 May 2024."},{"key":"e_1_3_2_1_34_1","unstructured":"The Go Programming Language. 2024 e. A Quick Guide to Go's Assembler. https:\/\/go.dev\/doc\/asm"},{"key":"e_1_3_2_1_35_1","volume-title":"2024 f. The Go Compiler. https:\/\/go.dev\/src\/cmd\/compile\/README. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024 f. The Go Compiler. https:\/\/go.dev\/src\/cmd\/compile\/README. Online; accessed 27 May 2024."},{"key":"e_1_3_2_1_36_1","volume-title":"2024 g. The Laws of Reflection. https:\/\/go.dev\/blog\/laws-of-reflection. Online","author":"Programming Language The Go","year":"2024","unstructured":"The Go Programming Language. 2024 g. The Laws of Reflection. https:\/\/go.dev\/blog\/laws-of-reflection. Online; accessed 28 May 2024."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Salt Lake City UT USA","acronym":"CCS '24"},"container-title":["Proceedings of the 2024 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689944.3696166","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689944.3696166","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T18:22:57Z","timestamp":1755973377000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689944.3696166"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,19]]},"references-count":36,"alternative-id":["10.1145\/3689944.3696166","10.1145\/3689944"],"URL":"https:\/\/doi.org\/10.1145\/3689944.3696166","relation":{},"subject":[],"published":{"date-parts":[[2023,11,19]]},"assertion":[{"value":"2024-11-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}