Pith. sign in

Paper Citation Record · LEDGER

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild

As of 14 August 2026, this Paper Citation Record lists 32 of 32 outbound references and 0 inbound Pith citation observations for arXiv:2606.26291.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.26291 v1

Coverage vector

measured 32 of 32 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-06-26T01:27:13.772082Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

32 of 32 outbound references displayed

  • verified exact6
  • verified fuzzy0
  • unresolved23
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch3

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 01da6446-458c-4d30-9c74-abd123f5747a · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 1

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:d7589867a619c605a442b740e8c158fb33cb5e345ed48659b5e0f2c33133c9d4

Observation 2f4630b4-2c46-4ad7-ade6-31bee919e764 · outbound

This paper cites A Serverless and Go Journey – Evolution of the Capital One Credit Offers API.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild A Serverless and Go Journey – Evolution of the Capital One Credit Offers API

Reference 2

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:02638cf171a03c955a63684ad13583c64943e5c4e48cd8ba6f07271a7a766d07

Observation 00fd61ac-4f50-47f3-b80e-84e4de12de46 · outbound

This paper cites Is Golang Still Growing? Go Language Popularity Trends in 2024.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Is Golang Still Growing? Go Language Popularity Trends in 2024

Reference 3

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:1d40f6d346eaab8d98f372dd7ba1c16e24f36ad6612eb6553c4780e48c6437b4

Observation 65467138-3897-43e2-a88a-a360cf1740b1 · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 4

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:9119d6620cb569c4e09124cc00b81db24c8d90a4602db1efb121a5c37664ab5b

Observation 263be669-8242-41f7-8072-f8bb585526a6 · outbound

This paper cites How to go from untrusted open source compo- nents to trusted artifacts.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild How to go from untrusted open source compo- nents to trusted artifacts

Reference 5

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:89ca8cbaee81d688552ae64cab78fb3b8be3df9199b3a460c6ddc366fa945d4b

Observation 5994c2a6-308e-4141-b9a6-2bb7506ea7bc · outbound

This paper cites ENISA THREAT LAND- SCAPE FOR SUPPLY CHAIN ATTACKS.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild ENISA THREAT LAND- SCAPE FOR SUPPLY CHAIN ATTACKS

Reference 6

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:df43f92b7acfd330a6d8f6b2308341f9dcc3548e3e47976760e89036f931bf41

Observation 4c3c5f91-0bf0-4a19-9dc7-01893842e2bb · outbound

This paper cites State of the Software Supply Chain Report.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild State of the Software Supply Chain Report

Reference 7

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:989427a4569a2a412bbeed1f76187be838140ec595ceb03449848d681786479b

Observation 62d6e45a-c38e-484f-89ee-e558009d7c78 · outbound

This paper cites Widespread Sup- ply Chain Compromise Impacting npm Ecosystem.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Widespread Sup- ply Chain Compromise Impacting npm Ecosystem

Reference 8

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:fba204aab62fcb872ea6255a37901d9a3c34006e2425f79286d4bbcb9f3fe4a4

Observation b4f418a6-1193-4f9d-b296-99fede4f711f · outbound

This paper cites event-stream incident report.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild event-stream incident report

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-07-04T15:49:56.411014Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:4b52c968636b50d00af824f626982f8cac47503d0738675e85be3b09f83968d5

Observation 8d705ac8-e0df-4996-a690-36da1ffdf473 · outbound

This paper cites Compromised PyTorch-nightly dependency chain be- tween December 25th and December 30th, 2022.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Compromised PyTorch-nightly dependency chain be- tween December 25th and December 30th, 2022

Reference 10

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:12d77a7c2131a00d5b7c8ca06fe10930270728759f462a928da86ee328f044a7

Observation db7c0f20-63eb-4d27-b444-ccb8389e9281 · outbound

This paper cites Someone copied our GitHub project, made it look more trustworthy by adding stars from many fake users, and then injected malicious code at runtime for potential users.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Someone copied our GitHub project, made it look more trustworthy by adding stars from many fake users, and then injected malicious code at runtime for potential users

Reference 11

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:4dfa971fa192585d00943540175c854c5bcf7de61184d548d61d30cc4d78381d

Observation c2e973f2-4d58-4fc2-93b0-b5622d9ac00c · outbound

This paper cites Attacks on Maven Proxy Repositories.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Attacks on Maven Proxy Repositories

Reference 12

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:4b66ff360af5771ac480f16b15b2202c98a73665c5c5664f1635a0fb4ca0d132

Observation 25a04594-c872-4ef8-b85f-77cf93ede95e · outbound

This paper cites Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T15:49:56.414269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:68b1388d3f0a24ff6669fb1e08e161e2bbee0a0f9bab853dddd05d7c041b273b

Observation ef371e49-6d1e-4463-877e-e453d686aa3a · outbound

This paper cites In: Proceedings of the 36th An- nual Computer Security Applications Conference (ACSAC ’20), pp.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild In: Proceedings of the 36th An- nual Computer Security Applications Conference (ACSAC ’20), pp

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-06-26T01:28:50.742734Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:ae7d5b4d5184c391acd2a8469ec7f8b3a9bd768d0ab38e56b847436175abe5ac

Observation a4b54ffe-6d48-4d05-bd21-4a5047f41521 · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 15

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:e5c71c8cc341c209e1dca34e35ef20e13742be690c2a90d4dfc73d1b79cbc639

Observation ac6269f1-7fda-42ec-a9a5-b885e1047d14 · outbound

This paper cites Millions of Malicious Repositories Flood GitHub.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Millions of Malicious Repositories Flood GitHub

Reference 16

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:d9cc01b38fd71b7b9eb786ed313bf1a75a26933c5da4f55902417629b0ee0595

Observation d1b57b37-db69-4cb6-b2dd-529166b33777 · outbound

This paper cites GitHub Docs:Reporting abuse or spam.https://docs.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild GitHub Docs:Reporting abuse or spam.https://docs

Reference 17

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:b458dffe249a052b4c0b46b4d867caab6db17877be31490b27ff3712f706a3e8

Observation ee8394c7-96b6-425d-bb07-c1a69029735c · outbound

This paper cites Over 100,000 Infected Repos Found on GitHub.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Over 100,000 Infected Repos Found on GitHub

Reference 18

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:d93b4b15183fe24a39344614b2c980699ec7058547b0d86d5239af5d0bc53a49

Observation d3efdd12-4ef9-4e19-bdd2-257309f5e125 · outbound

This paper cites Flash Report: GitHub Repositories Targeted in Mali- cious Cyber Activity.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Flash Report: GitHub Repositories Targeted in Mali- cious Cyber Activity

Reference 19

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:cc02fb54259e47f3abd45588f8421795707723a530a650cac9fa73b3471c8341

Observation fc67921a-4060-4e6d-b105-f86ab3311fba · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 20

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:c12d36f8dbadf9f49f641ba81c45d6a0ea1dcdee68c7ca3c05afd06dbc062af1

Observation 17f6208a-e837-41c9-9508-36d669d1ace2 · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 21

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:addb1a240542e9a046913c1b5a5ca1664b5c33b7e732c964b4392098ad1c43bd

Observation 98a65fef-aa75-4dd6-abc4-b32dd73cb024 · outbound

This paper cites Go Supply Chain Attack: Ma- licious Package Exploits Go Module Proxy Caching for Persis- tence.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Go Supply Chain Attack: Ma- licious Package Exploits Go Module Proxy Caching for Persis- tence

Reference 22

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:d2f4e4b2cf87e5fabea2549939afd863cdc6f8e7ea91df7d2ad7f93b22bb86b8

Observation ec14796b-3fe3-479c-b06a-cc93e70cc085 · outbound

This paper cites dev/blog/module-mirror-launch, last accessed 2026/04/10.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild dev/blog/module-mirror-launch, last accessed 2026/04/10

Reference 23

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:02112dfb63b2bd2cdea5c7fa60805d81df06670b52c193eeefb498d88aab4537

Observation e1b7ced1-d08e-492c-8c60-f221c159f391 · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 24

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:611f11849b3afd9ea39c190c846f061afdfa440c29ee951442a7a2266a1f59e1

Observation c0055760-ce73-441a-9fa2-499e6d328a86 · outbound

This paper cites an unresolved cited work.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Unresolved cited work

Reference 25

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:c3937b8a460f6ebfdc8c602cc0964c3aba743cdcf07d2c787f1eff45cfe3e7e5

Observation 8392b7c6-84ca-4289-a5de-e4db2446da47 · outbound

This paper cites In: 28th USENIX Security Symposium (USENIX Security ’19), pp.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild In: 28th USENIX Security Symposium (USENIX Security ’19), pp

Reference 26

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T15:49:56.398758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:0ec2171ed2947339eaf0369f9f45dba41024b911c45351e8aa42677778383623

Observation a55e2d73-f277-43b5-9670-d1a1ca6e8348 · outbound

This paper cites Taxonomy of Attacks on Open-Source Software Supply Chains.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild Taxonomy of Attacks on Open-Source Software Supply Chains

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-07-04T15:49:56.406200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:ef59fc59432a1afede24599243f1af60453c68f27a02753690b304bbd83593ad

Observation 685d49c8-a169-4052-b1d3-a7abc7430d07 · outbound

This paper cites In: Network and Distributed System Security (NDSS ’21) Symposium.https://www.ndss-symposium.org/wp-content/uploads/ndss2021_ 1B-1_23055_paper.pdf.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild In: Network and Distributed System Security (NDSS ’21) Symposium.https://www.ndss-symposium.org/wp-content/uploads/ndss2021_ 1B-1_23055_paper.pdf

Reference 28

Resolution
unresolved
no resolver link, observed 2026-06-26T01:27:13.772082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:58f21f895fc8d7584ddb80989c5ea2baceade8f55dad6f4a0d3ed8b0a62e9ce4

Observation 639b6457-1f5b-4d7a-9f4f-5523f13134b5 · outbound

This paper cites In: Proceedings of the 17th International Conference on Detection of Intrusions and Malware, and Vulnera- bility Assessment (DIMVA).

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild In: Proceedings of the 17th International Conference on Detection of Intrusions and Malware, and Vulnera- bility Assessment (DIMVA)

Reference 29

Resolution
verified exact
doi, observed 2026-06-26T01:28:50.736511Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:b9abde7707f8676a1b6bc483f96aa11cfc9fed4283998c37fc16a2b84239e896

Observation 9e695e3f-93cc-43ed-8cc3-46cfc1193020 · outbound

This paper cites InProceedings of the 2024 Workshop on Software Supply Chain Offen- sive Research and Ecosystem Defenses (SCORED ’24).

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild InProceedings of the 2024 Workshop on Software Supply Chain Offen- sive Research and Ecosystem Defenses (SCORED ’24)

Reference 30

Resolution
metadata mismatch
arxiv_id, observed 2026-06-26T01:28:50.745366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:da1e1752a5c17bbac45f2c5ee065054d7ee11c461f09fe756f17d6875532c692

Observation 581399a8-6cad-4cf9-8d5a-53be48e024d8 · outbound

This paper cites GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-07-04T15:49:56.402401Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:209d20431532f39f7f43fe2f076ebd1b48d0eba4c2f529b9f60d4845b28d114e

Observation f10ef833-89c2-467a-87c4-e3e848cc355a · outbound

This paper cites An empirical study on low GPU utilization of deep learning jobs.

Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild An empirical study on low GPU utilization of deep learning jobs

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-06-26T01:28:50.739966Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T01:27:13.772082Z digest=sha256:4b41e8923067f90e31a293ce20291b9ec3d1ccd4ed41d3c7afd9fa677540abcf

Pith citing papers

No inbound Pith citation observations are available.