GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted package maintainer’s account, publish a malicious update, and rely on automated dependency tools to distribute it before the package is detected and removed. In September 2025, attackers reportedly phished an npm maintainer. They used the access to publish trojanized versions of popular packages, including chalk and debug. The affected packages received more than 222 billion downloads each week. The malicious code replaced cryptocurrency wallet...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!