{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T15:59:11Z","timestamp":1785340751210,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":20,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:00:00Z","timestamp":1760313600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3733827.3765523","type":"proceedings-article","created":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T12:47:16Z","timestamp":1785329236000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0028-5010","authenticated-orcid":false,"given":"Frank","family":"Reyes","sequence":"first","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3662-8904","authenticated-orcid":false,"given":"Federico","family":"Bono","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2263-7902","authenticated-orcid":false,"given":"Aman","family":"Sharma","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4015-4640","authenticated-orcid":false,"given":"Benoit","family":"Baudry","sequence":"additional","affiliation":[{"name":"Universit\u00e9 de Montr\u00e9al, Montr\u00e9al, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3505-3383","authenticated-orcid":false,"given":"Martin","family":"Monperrus","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,29]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"G.J.T. Bot. 2023. Uncovering secrets of the Maven Repository: Java Build Aspects. Ph.\u00a0D. Dissertation. https:\/\/repository.tudelft.nl\/record\/uuid:038ba3fe-f235-467e-9d14-251e7c57d068"},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455841"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510078"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","unstructured":"Tobias Dam Lukas\u00a0Daniel Klausner and Sebastian Schrittwieser. 2020. Typosquatting for Fun and Profit: Cross-Country Analysis of Pop-Up Scam. Journal of Cyber Security and Mobility (March 2020). 10.13052\/jcsm2245-1439.924arXiv:https:\/\/arXiv.org\/abs\/2004.01749 [cs].","DOI":"10.13052\/jcsm2245-1439.924"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2019.00061"},{"key":"e_1_3_3_2_7_2","unstructured":"Henrik Hauser. 2022. Hardening the Software Supply Chain: Developing a System to Prevent Dependency Confusion Attacks in Cloud Based Continuous Integration and Deployment Processes. Ph.\u00a0D. Dissertation."},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS62785.2024.00057"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","unstructured":"Wenxin Jiang Berk \u00c7akar Mikola Lysenko and James\u00a0C. Davis. 2025. ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale. 10.48550\/arXiv.2502.20528arXiv:https:\/\/arXiv.org\/abs\/2502.20528 [cs].","DOI":"10.48550\/arXiv.2502.20528"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","unstructured":"Piergiorgio Ladisa Henrik Plate Matias Martinez and Olivier Barais. 2022. Taxonomy of Attacks on Open-Source Software Supply Chains. 10.1109\/SP46215.2023.00010arXiv:https:\/\/arXiv.org\/abs\/2204.04008 [cs].","DOI":"10.1109\/SP46215.2023.00010"},{"key":"e_1_3_3_2_11_2","unstructured":"Ravie Lakshmanan. 2024. MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries. https:\/\/thehackernews.com\/2024\/01\/hackers-hijack-popular-java-and-android.html Section: Article."},{"key":"e_1_3_3_2_12_2","unstructured":"Guannan Liu Xing Gao Haining Wang and Kun Sun. 2022. Exploring the Unchartered Space of Container Registry Typosquatting. 35\u201351. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/liu-guannan"},{"key":"e_1_3_3_2_13_2","series-title":"(SEC \u201923)","first-page":"3439","volume-title":"Proceedings of the 32nd USENIX Conference on Security Symposium","author":"Neupane Shradha","year":"2023","unstructured":"Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, and Lorenzo De\u00a0Carli. 2023. Beyond typosquatting: an in-depth look at package confusion. In Proceedings of the 32nd USENIX Conference on Security Symposium(SEC \u201923). USENIX Association, USA, 3439\u20133456."},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180184"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","unstructured":"Imen Sayar Alexandre Bartel Eric Bodden and Yves Le\u00a0Traon. 2023. An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities. ACM Transactions on Software Engineering and Methodology 32 1 (Feb. 2023) 25:1\u201325:45. 10.1145\/3554732","DOI":"10.1145\/3554732"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","unstructured":"Hossein Siadati Sima Jafarikhah Elif Sahin Terrence\u00a0Brent Hernandez Elijah\u00a0Lorenzo Tripp and Denis Khryashchev. 2024. DevPhish: Exploring Social Engineering in Software Supply Chain Attacks on Developers. 10.48550\/arXiv.2402.18401arXiv:https:\/\/arXiv.org\/abs\/2402.18401 [cs].","DOI":"10.48550\/arXiv.2402.18401"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3560437"},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236056"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00068"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"publisher","unstructured":"Ying Wang Rongxin Wu Chao Wang Ming Wen Yepang Liu Shing-Chi Cheung Hai Yu Chang Xu and Zhiliang Zhu. 2022. Will Dependency Conflicts Affect My Program\u2019s Semantics? IEEE Transactions on Software Engineering 48 7 (July 2022) 2295\u20132316. 10.1109\/TSE.2021.3057767Conference Name: IEEE Transactions on Software Engineering.","DOI":"10.1109\/TSE.2021.3057767"}],"event":{"name":"SCORED '25: Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses","location":"Taipei , Taiwan","acronym":"SCORED '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733827.3765523","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T15:12:23Z","timestamp":1785337943000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733827.3765523"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":20,"alternative-id":["10.1145\/3733827.3765523","10.1145\/3733827"],"URL":"https:\/\/doi.org\/10.1145\/3733827.3765523","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2026-07-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}