CVE-Based Scanners Miss the Fastest Supply-Chain Attacks, Analysts Warn
Security scanners that rely on CVE databases are structurally blind to supply-chain attacks because a CVE can only be assigned after a flaw is discovered, catalogued, and published — a process that takes time attackers do not wait for. High-profile incidents including the event-stream npm compromise in 2018, the ua-parser-js hijack in 2021, and the polyfill.io domain sale in 2024 all caused damage before any CVE existed. Even xz-utils, which did receive CVE-2024-3094, had visible human warning signs — a new contributor slowly gaining trust and a tarball diverging from its git source — nearly a year before the identifier was assigned. Analysts argue that meaningful early detection requires monitoring project-level signals such as maintainer turnover, sudden drops in commit activity, ownership transfers, and artefact-to-source mismatches. These indicators consistently appear before an advisory is written and do not depend on a vulnerability number to be actionable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in