Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game? @FIRSTdotorg
Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 12 hours ago
Art Manion (Tharros Labs, US), Caitlin Condon (VulnCheck, US), David Welch (HeroDevs, US), Shelby Cunningham (GitHub, US)

2025 was a year of attention-grabbing malware campaigns targeting the open-source supply chain. From a campaign that affected a single package (tj-actions/changed-files) to massive supply chain compromises like the Shai Hulud attacks against npm, vulnerability management teams need ways to keep track of compromised packages that provides accurate information in a timely fashion. While CVE rules prohibit the use of CVE for tracking general-purpose malicious code, the rules do allow issuing a CVE ID to a legitimate package infected with malware. This raises a question: Is CVE the best way to track these supply chain compromises? This panel discusses situations in which CVE helped to facilitate tracking of a single-package supply chain attack, while acknowledging the drawbacks that arise when CVE rules are applied to campaigns that affect hundreds of packages

---

Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).

Caitlin Condon is the VP of research at VulnCheck, where she works on initial access intelligence, emerging threat response, and coordinated vulnerability disclosure with some of the kindest, most talented researchers and analysts around. She previously led research and Metasploit development at Rapid7. Caitlin also chairs the CVE Program's Researcher Working Group (RWG), which you should totally join if you’re a researcher or bug bounty CNA!

David Welch is a seasoned industry leader with 20+ years of experience. Passionate about open source software, security, and compliance, he brings a unique perspective to the evolving tech landscape. As Chief Architect at HeroDevs, David spearheads the technical direction of the Never-Ending Support program, delivering Long-Term Support for end-of-life open-source projects.

Shelby Cunningham has been an advisory curator for the GitHub Advisory Database (GHAD) for five years. Her duties include, but are not limited to, organizing and publishing vulnerability information for the GHAD and gathering vulnerability information from project maintainers on GitHub to submit to the CVE list. Shelby has supported best security practices in the open source software community by advising projects that are part of the GitHub Secure Open Source Fund. In 2025, she responded to multiple incidents involving compromise of legitimate packages in ecosystems supported by the GHAD.
Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise ParticipantsEpisode 63: John Hollenberger, Fortinet, FIRSTCON26 SpeakerRevolutionizing Malware Analysis with Agentic AI: Lessons and InnovationsIdentifying Exploited and Likely-to-Be-Exploited VulnerabilitiesTaming the Scanner Storm: How VEX Brings Context to Vulnerability DataEpisode 62: Tim Brown, Team8, former SolarWinds CISO, FIRSTCON26 KeynoteUnmasking MSC FilesImproving Security Across Nations with FIRST: Dr. Lisa Bradley, FIRST PSIRT SIG MemberFlipping the Criticality Funnel, A Practical Path to Real PrioritizationForecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ...IC5 – Integrated CERT Cyber Communications, Collaboration & Coordination Framework
FIRST |

Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER