GitHub rolled out new supply-chain protections across GitHub Actions and npm to curb attacks that abuse CI/CD workflows and malicious package publishing. On public repositories hosted on GitHub.com, workflow runs that GitHub flags as suspicious are now automatically paused until a repository collaborator with write access approves them through an authenticated web session. The safeguard is enabled by default and is aimed at attacks involving compromised GitHub credentials, malicious workflow files, and workflow-based secret theft or package tampering, though GitHub has not disclosed detection logic and said the control does not guarantee every malicious run will be caught.
GitHub also introduced publish-time malware scanning for npm packages, shifting enforcement from scanning after publication to gating releases before they become available. Under the new process, a package can be published, held for review, or blocked based on scan results, alongside new dual-use metadata requirements such as contentPolicy and DISCLOSURE. The changes build on GitHub’s broader response to open-source supply-chain attacks, including guidance to pin third-party Actions to full commit SHAs, avoid unsafe pull_request_target usage, use OpenID Connect for secretless authentication, and rely on trusted publishing across ecosystems including npm, PyPI, NuGet, RubyGems, and Crates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
As part of the July 28, 2026 publish-time scanning changes, npm introduced a contentPolicy field and required dual-use packages to include a text-only DISCLOSURE file and use a publishing method that enforces 2FA.
On July 28, 2026, npm announced that newly published packages will be scanned before becoming installable, with packages either published, held for manual review, or blocked based on scan results.
On July 28, 2026, GitHub announced that suspicious GitHub Actions workflow runs in public repositories on GitHub.com will be automatically paused until a repository collaborator with write access approves them in an authenticated web session.
On June 18, 2026, GitHub updated actions/checkout so version 7 and supported backported versions reject common configurations that retrieve unreviewed fork code during privileged pull_request_target or certain workflow_run executions.
In an April 1, 2026 blog post, GitHub said npm scans every package version for malware and that human reviewers validate detections before enforcement because false positives at npm scale would be highly disruptive.
GitHub cited the late-2025 Shai-Hulud attacks as a major supply-chain incident that helped drive changes to its npm and GitHub Actions security roadmap.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
opensourcemalware.com
Open sourcetechrepublic.com
Open sourcegithub.blog
Open sourcegithub.blog
Open sourcegithub.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.