GitHub and the Python Package Index (PyPI) introduced new time-based protections aimed at slowing the spread of malicious open-source packages and preventing tampering with trusted releases. GitHub added a default 72-hour cooldown for non-security Dependabot updates, delaying automatic pull requests for newly published package versions so suspicious releases have more time to be detected and removed before broad adoption.
PyPI said it will block maintainers from uploading new files to package releases more than 14 days old, a safeguard designed to stop attackers from poisoning long-stable versions after compromising maintainer accounts, tokens, or publishing workflows. PyPI said it has not seen this technique abused to date, but noted there is no technical barrier to it; the restriction is expected to be enforced after the Upload 2.0 API and staged previews are standardized under PEP 694. Both platforms said the changes respond to repeated software supply-chain incidents, while GitHub also urged developers to keep using controls such as lockfiles, scoped tokens, and disabling unnecessary CI install scripts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
PyPI announced a policy to prevent maintainers from adding new files to package releases more than 14 days after publication, aiming to stop attackers from poisoning older trusted versions after account or token compromise.
GitHub introduced a default three-day cooldown before Dependabot automatically proposes non-security updates to newly published packages, intended to reduce rapid adoption of malicious releases in supply-chain attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.