GitHub has changed Dependabot to wait three days before opening pull requests for non-security version updates, aiming to keep fast-moving malicious package releases out of automated developer workflows. The company said the change was driven by repeated software supply-chain incidents in which poisoned npm releases were detected and removed within hours, but still had enough time to be pulled into builds. GitHub pointed to a 2025 npm compromise in which an attacker phished a maintainer and published malicious versions of widely used packages including chalk and debug, with code that rewrote cryptocurrency wallet addresses before the packages were taken down roughly two hours later. Security updates tied to known advisories are not delayed and will still be issued immediately.
The move aligns with broader industry guidance that the first hours after a package is published are the highest-risk period for dependency consumers. Research cited similar attacks affecting 18 npm packages with more than 2.6 billion weekly downloads and the Nx build attack, which remained live for about four hours, reinforcing recommendations to delay automated updates by 24 to 48 hours or longer. GitHub said the npm ecosystem logged more than 6,500 malware advisories in the year ending May 2026 and urged teams to combine cooldowns with other controls, including lockfiles, careful review before merge, scoped CI tokens, disabling install scripts where possible, and pinning dependency versions to reduce supply-chain exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The compromised npm packages cited by GitHub were taken down about two hours after publication. GitHub highlighted that this was still long enough for automated dependency update tools to ingest the poisoned releases.
In September 2025, an attacker phished an npm maintainer and published malicious versions of chalk, debug, and other widely used packages. The malware rewrote cryptocurrency wallet addresses, creating a short but dangerous supply-chain exposure window.
On 2026-07-23, GitHub announced that Dependabot now waits three days by default before opening non-security version update pull requests. The change is intended to reduce exposure to fast-moving software supply-chain attacks while leaving security updates unaffected.
On 2026-01-12, Semgrep published an analysis of npm supply-chain attacks, including incidents involving 18 compromised packages and the Nx build attack. The post recommended mitigations such as pinning versions, blocking install scripts, and delaying automated updates by 24 to 48 hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcehelpnetsecurity.com
Open sourcegithub.blog
Open sourcesemgrep.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.