A mixed-methods analysis of the XZ Utils attack shows the attacker weaponized routine software engineering practices, especially non-code contributions, to gain maintainer trust and hide malicious commits.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.SE 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
A mixed-methods analysis of the XZ Utils attack shows the attacker weaponized routine software engineering practices, especially non-code contributions, to gain maintainer trust and hide malicious commits.