DevPhish: Exploring Social Engineering in Software Supply Chain Attacks on Developers -- IEEE 15th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference (UEMCON) Academic Article uri icon

Abstract

  • The Software Supply Chain (SSC) has capturedconsiderable attention from attackers seeking to infiltrate systemsand undermine organizations. There is evidence indicating thatadversaries utilize Social Engineering (SocE) techniques specif-ically aimed at software developers. That is, they interact withdevelopers at critical steps in the Software Development Life Cycle(SDLC), such as accessing Github repositories, incorporatingcode dependencies, and obtaining approval for Pull Requests (PR)to introduce malicious code. This paper aims to comprehensivelyexplore the existing and emerging SocE tactics employed byadversaries to trick Software Engineers (SWEs) into deliveringmalicious software. By analyzing a diverse range of resources,which encompass established academic literature and real-worldincidents, the paper systematically presents an overview of thesemanipulative strategies within the realm of the SSC. Such insightsprove highly beneficial for threat modeling and security gapanalysis.

Published In