{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2020:FH5KCAWACZZXRV2SXAN2RRXQNM","short_pith_number":"pith:FH5KCAWA","canonical_record":{"source":{"id":"2005.09535","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-19T15:49:23Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"e614ce74e14106840c200c6b65bd4a064e1e57db46babb9d60513fcae1d8c1bb","abstract_canon_sha256":"051a814af08731fa731fa7406b07370c132bfc1c7f6c86997dc01ab313306a32"},"schema_version":"1.0"},"canonical_sha256":"29faa102c0167378d752b81ba8c6f06b1b1336931b45fde7ee5786ddd28dd687","source":{"kind":"arxiv","id":"2005.09535","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2005.09535","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"arxiv_version","alias_value":"2005.09535v1","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2005.09535","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_12","alias_value":"FH5KCAWACZZX","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_16","alias_value":"FH5KCAWACZZXRV2S","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_8","alias_value":"FH5KCAWA","created_at":"2026-07-05T01:03:50Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2020:FH5KCAWACZZXRV2SXAN2RRXQNM","target":"record","payload":{"canonical_record":{"source":{"id":"2005.09535","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-19T15:49:23Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"e614ce74e14106840c200c6b65bd4a064e1e57db46babb9d60513fcae1d8c1bb","abstract_canon_sha256":"051a814af08731fa731fa7406b07370c132bfc1c7f6c86997dc01ab313306a32"},"schema_version":"1.0"},"canonical_sha256":"29faa102c0167378d752b81ba8c6f06b1b1336931b45fde7ee5786ddd28dd687","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:03:50.905796Z","signature_b64":"3TrPHB2Kp/WHJs7p+Sjsv/27qS+qG3+NfdO9EfWOxBvhfLS0eAl1NFyF22uGyW7L7QY422L23s9S19Fi/SmQBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"29faa102c0167378d752b81ba8c6f06b1b1336931b45fde7ee5786ddd28dd687","last_reissued_at":"2026-07-05T01:03:50.905393Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:03:50.905393Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2005.09535","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T01:03:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4fki/WeoMRTozcceandI8h1TzQ18sPew9cgqGRBjBqW9Hq/rgesXDVUZfd8L5khvhHENL8Rk8Sg9RPaB8oqdCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T03:20:50.133954Z"},"content_sha256":"1b1dcbc3a522f661e5b69849917b36d867d3db1de5dd0eec8215e972ca63c890","schema_version":"1.0","event_id":"sha256:1b1dcbc3a522f661e5b69849917b36d867d3db1de5dd0eec8215e972ca63c890"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2020:FH5KCAWACZZXRV2SXAN2RRXQNM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Arnold Sykosch, Henrik Plate, Marc Ohm, Michael Meier","submitted_at":"2020-05-19T15:49:23Z","abstract_excerpt":"A software supply chain attack is characterized by the injection of malicious code into a software package in order to compromise dependent systems further down the chain. Recent years saw a number of supply chain attacks that leverage the increasing use of open source during software development, which is facilitated by dependency managers that automatically resolve, download and install hundreds of open source packages throughout the software life cycle. This paper presents a dataset of 174 malicious software packages that were used in real-world attacks on open source software supply chains"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2005.09535","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2005.09535/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T01:03:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JeI6aO/RTyxfKj4E2PTacrR7yC5nmhbzRvjhCiw0e4AL662f0PHIjNSa80e0t3kBPFglnLO5E+7WM6cbI4YpBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T03:20:50.134435Z"},"content_sha256":"627edb4511d006476f1d60c99aa319803dc43cb9fc40faaf64086c7bbb15ad17","schema_version":"1.0","event_id":"sha256:627edb4511d006476f1d60c99aa319803dc43cb9fc40faaf64086c7bbb15ad17"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/bundle.json","state_url":"https://pith.science/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-05T03:20:50Z","links":{"resolver":"https://pith.science/pith/FH5KCAWACZZXRV2SXAN2RRXQNM","bundle":"https://pith.science/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/bundle.json","state":"https://pith.science/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/FH5KCAWACZZXRV2SXAN2RRXQNM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2020:FH5KCAWACZZXRV2SXAN2RRXQNM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"051a814af08731fa731fa7406b07370c132bfc1c7f6c86997dc01ab313306a32","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-19T15:49:23Z","title_canon_sha256":"e614ce74e14106840c200c6b65bd4a064e1e57db46babb9d60513fcae1d8c1bb"},"schema_version":"1.0","source":{"id":"2005.09535","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2005.09535","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"arxiv_version","alias_value":"2005.09535v1","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2005.09535","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_12","alias_value":"FH5KCAWACZZX","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_16","alias_value":"FH5KCAWACZZXRV2S","created_at":"2026-07-05T01:03:50Z"},{"alias_kind":"pith_short_8","alias_value":"FH5KCAWA","created_at":"2026-07-05T01:03:50Z"}],"graph_snapshots":[{"event_id":"sha256:627edb4511d006476f1d60c99aa319803dc43cb9fc40faaf64086c7bbb15ad17","target":"graph","created_at":"2026-07-05T01:03:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2005.09535/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"A software supply chain attack is characterized by the injection of malicious code into a software package in order to compromise dependent systems further down the chain. Recent years saw a number of supply chain attacks that leverage the increasing use of open source during software development, which is facilitated by dependency managers that automatically resolve, download and install hundreds of open source packages throughout the software life cycle. This paper presents a dataset of 174 malicious software packages that were used in real-world attacks on open source software supply chains","authors_text":"Arnold Sykosch, Henrik Plate, Marc Ohm, Michael Meier","cross_cats":["cs.SE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-19T15:49:23Z","title":"Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2005.09535","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1b1dcbc3a522f661e5b69849917b36d867d3db1de5dd0eec8215e972ca63c890","target":"record","created_at":"2026-07-05T01:03:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"051a814af08731fa731fa7406b07370c132bfc1c7f6c86997dc01ab313306a32","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-19T15:49:23Z","title_canon_sha256":"e614ce74e14106840c200c6b65bd4a064e1e57db46babb9d60513fcae1d8c1bb"},"schema_version":"1.0","source":{"id":"2005.09535","kind":"arxiv","version":1}},"canonical_sha256":"29faa102c0167378d752b81ba8c6f06b1b1336931b45fde7ee5786ddd28dd687","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"29faa102c0167378d752b81ba8c6f06b1b1336931b45fde7ee5786ddd28dd687","first_computed_at":"2026-07-05T01:03:50.905393Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T01:03:50.905393Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"3TrPHB2Kp/WHJs7p+Sjsv/27qS+qG3+NfdO9EfWOxBvhfLS0eAl1NFyF22uGyW7L7QY422L23s9S19Fi/SmQBw==","signature_status":"signed_v1","signed_at":"2026-07-05T01:03:50.905796Z","signed_message":"canonical_sha256_bytes"},"source_id":"2005.09535","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1b1dcbc3a522f661e5b69849917b36d867d3db1de5dd0eec8215e972ca63c890","sha256:627edb4511d006476f1d60c99aa319803dc43cb9fc40faaf64086c7bbb15ad17"],"state_sha256":"f2cb2f38dcf1ff36e4c01f38793429b3c695f6d322bbfb5f92ba00f797568a97"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dNQ67RLdPhoIW9uJSYFKlke965V3Fh5G5ot3jV6XKMaIV8BVSCIENUPi9r/cRG6RudPEbnKTWLPBuvlVtlCIAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-05T03:20:50.137809Z","bundle_sha256":"845ad3b0c100c9ead59b31c0139470e9a4099070527e76fc942484c2ce177949"}}