logo

GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

ID: 6d508ad2-0d08-5d62-8484-300e495bbf4a

STIX ID: report--6d508ad2-0d08-5d62-8484-300e495bbf4a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Abinaya

...
...

GitHub is adding a default three-day cooldown to Dependabot version updates after incidents where attackers phished npm maintainers and published trojanized package releases (e.g., chalk, debug) that could redirect cryptocurrency payments; automated dependency tools previously created pull requests from those malicious releases before they were detected and removed. The change delays non-security version updates to give maintainers, researchers, and scanners time to detect and remove malicious releases, while keeping security updates immediate; the report notes a large and growing volume of npm malware advisories (about 6,500 in the year ending May 2026) and stresses that cooldowns are a mitigation, not a complete solution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.