[2204.04008] Taxonomy of Attacks on Open-Source Software Supply Chains