Appendix C: References and Further Reading¶
The sources below are cited throughout this handbook and are grouped here for quick reference.
Standards and Frameworks¶
- MITRE AADAPT
- MITRE ATT&CK
- MITRE ATT&CK - Technique T1195: Supply Chain Compromise
- OWASP Vulnerability Disclosure Cheat Sheet
- CycloneDX 1.6 JSON Specification
- EIP-1193: Ethereum Provider JavaScript API
- EIP-1559: Fee Market Change for ETH 1.0 Chain
- EIP-3085: Wallet Add Ethereum Chain RPC Method
- EIP-712: Typed Structured Data Hashing and Signing
- OpenVEX Specification
- OWASP Mobile Application Security Verification Standard (MASVS)
- OWASP Top 10:2025
- OWASP Smart Contract Security Testing Guide / SCSVS / SCWE (scs.owasp.org)
- OWASP Web3 Attack Vectors Top 15
- SLSA v1.2 Specification
- SLSA v1.2 - Build Requirements
- SLSA v1.2 - Source Requirements
- SLSA v1.2 - Threats and Mitigations
- SLSA v1.2 - What's New
- SPDX 3.0 Specification
- CISA VEX Working Group
- CISA, Minimum Requirements for Vulnerability Exploitability eXchange (VEX)
- ISO/IEC 30111: Vulnerability Handling Processes
- ISO/IEC 29147: Vulnerability Disclosure
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure (security.txt)
Incidents and Case Studies¶
- XcodeGhost (Wikipedia)
- event-stream Malicious Dependency Incident - GitHub Issue #116
- Alex Birsan - Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies (2021)
- Doctor Web - Malicious npm Package Analysis
- Socket - npm Author "Qix" Compromised in Major Supply Chain Attack
- Socket.dev - Supply Chain Attack on the @solana/web3.js Library
- The Hacker News - Crypto Trading Firm Wintermute Loses $160M in Hack
- The Hacker News - Researchers Uncover Backdoor in Solana's Web3.js npm Library
- Aikido Security - npm debug and chalk Packages Compromised
- Aikido Security - XRP Supply Chain Attack: Official npm Package Infected with Crypto-Stealing Backdoor
- CISA Alert - Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066)
- Halborn - Explained: The Profanity Address Generator Hack (September 2022)
- Ledger - A Letter from Ledger Chairman & CEO Pascal Gauthier Regarding the Ledger Connect Kit Exploit
- NCC Group - In-Depth Technical Analysis of the Bybit Hack
- XRPL.org - Vulnerability Disclosure Report: xrpl.js Bug (April 2025)
Tools and Documentation¶
- npm Documentation - Generating Provenance Statements
- npm Documentation - Trusted Publishers
- Sigstore Documentation (Cosign, Fulcio, Rekor)
- GitHub Security Advisories (GHSA) Database
- National Vulnerability Database (NVD)
- OSV.dev - Open Source Vulnerabilities Database
- Reproducible Builds Project
- OpenSSF Scorecard
- Sourcify - Contract Source Verification
- WalletConnect Network