Accepted Submissions
Research Papers
-
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort, Aleksandr Churilov, Independent Researcher
-
SandScope: A Behavioral Audit Layer for MCP Tools in LLM Agent Supply Chains Zhuoran Tan, University of Glasgow; Run Hao, Aarhus University; Jeremy Singer, University of Glasgow; Yutian Tang, University of Glasgow Christos Anagnostopoulos, University of Glasgow
-
Over the Shoulder: Improving SBOM Accuracy by Watching the Build Sanchit Sahay, NYU; Vyom Yadav, unaffiliated; Abhishek Reddypalle, Purdue University; Uk Jang, NYU; Marco De Vincenzi, NYU; Santiago Torres-Arias, Purdue University; Justin Cappos, NYU; Sanchit Sahay, NYU
-
When SBOMs Differ: A Large-Scale Empirical Study of Generation, Dependency Structure, and Regulatory Alignment Lukas Gehrke, Technical University of Munich; Adrian Stein, Technical University of Munich; Dan Glaman, Technical University of Munich; Fabian Franzen, Technical University of Munich; Jens Grossklags, Technical University of Munich
-
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis Romain Lefeuvre, University of Rennes, Inria, CNRS, IRISA; Charly Reux, University of Rennes, Inria, CNRS, IRISA; Stefano Zacchiroli, LTCI, Telecom Paris, Institut Polytechnique de Paris; Olivier Barais, University of Rennes, Inria, CNRS, IRISA; Benoit Combemale, University of Rennes, Inria, CNRS, IRISA
-
Mind the Gap: How SBOM Specification Ambiguities Lead to Divergent Software Bills of Materials. An Empirical Tool Study Alan Prado, Univ. Rennes, Inria, CNRS, IRISA; Olivier Zendra, Univ. Rennes, Inria, CNRS, IRISA; Philippe Boinot, ANSSI; Olivier Barais, Univ. Rennes, Inria, CNRS, IRISA
-
Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations (BEST PAPER AWARDEE) Abhishek Reddypalle Purdue University; Dennis Roellke, Bloomberg; Santiago Torres-Arias, Purdue University;
-
Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation Julien Malka, Polytechnic Institute of Paris; Aman Sharma, KTH Royal Institute of Technology; Martin Monperrus, KTH Royal Institute of Technology; Stefano Zacchiroli, Polytechnic Institute of Paris; Theo Zimmermann, Telecom Paris
-
Hurry Up and Wait: Malware Detection Timelines and Minimum Release Age for npm Dominic Tassio, University of Kansas; Thanoshan Malavarayar Vijayanandan, University of Calgary; Caleb Morse, University of Kansas; Lorenzo De Carli, University of Calgary; Drew Davidson, University of Kansas
-
No Snake Oil: Verifying Python Package Builds Jens Dietrich, Victoria University of Wellington; Spencer Sun, Victoria University of Wellington; Tim W. White, Oracle Inc; Behnaz Hassanshahi, Oracle Inc
-
Librarian Catches Thief: Surfacing Supply Chain Attack Campaigns via Document Similarity in an AI Agent Skill Registry Gale Fagan, Edgewood University
-
When Dependencies Become Lemons: A Multivocal Review of Cheap Trust Signal Collapse in the Software Supply Chain Ranindya Paramitha, North Carolina State University; Christian Kastner, Carnegie Mellon University; Laurie Williams, North Carolina State University
-
When Models Meet Loaders: Deserialization Risk in Huggingface Xiang Guo, Victoria University of Wellington; Shawn Rasheed, Victoria University of Wellington; Heitor Gomes, Victoria University of Wellington; Timothee Riom, Victoria University of Wellington; Jens Dietrich, Victoria University of Wellington
Systemization of Knowledge (SoK) Papers
- What Software Supply Chain Security Can Learn from Decades of Physical Supply Chain Risk Management Linus Kühl, FH; Michael Dircksen, FH Münster
Security in Practice Talks
- Canary in the Code Mine: Predictive Risk Scoring for Open-Source Supply Chain Security, Timothy Brennan, The George Washington University
- Ghost In The Codebase - Why Your LLM Needs a SCA/SAST Babysitter Luca Galli, Open Systems AG