Skip to content
GitHub Dependabot malware alerts now cover eight ecosystems

GitHub Dependabot malware alerts now cover eight ecosystems

Feeds2.Feedburner Mirko Zorz August 10, 2026

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launched in 2023 with more than 15,000 reports and has grown daily since, covering typosquats, dependency-confusion … More →

Extracted Entities

Attack Types (1)

Tools (1)