Crypto Ticker:
sysadmin from Cyber Security News

GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

Abinaya
5 hours ago
4 Views
0 Comments
GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted package maintainer’s account, publish a malicious update, and rely on automated dependency tools to distribute it before the package is detected and removed. In September 2025, attackers reportedly phished an npm maintainer. They used the access to publish trojanized versions of popular packages, including chalk and debug. The affected packages received more than 222 billion downloads each week. The malicious code replaced cryptocurrency wallet...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!