Skip to content

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

Gbhackers Divya August 10, 2026

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands […]

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Tools (1)