GitHub has expanded its malware advisory pipeline and Dependabot malware alerts beyond npm to cover eight major package ecosystems by ingesting malicious package data from OpenSSF’s malicious-packages repository into the GitHub Advisory Database. The broader coverage now includes npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, allowing repositories, organizations, and enterprises that opt in to receive alerts when malicious dependencies are detected in current packages or through advisory backfill.
To support the expansion, GitHub built a single importer that validates OSV records, normalizes ecosystem and version data, handles withdrawn advisories, and prevents circular re-import of GitHub-originated malware advisories tagged ghsa-malware. Because these malware advisories are auto-published without manual review to speed response times, GitHub added safeguards including batch caps, provenance tracking to upstream commits, and batch-level rollback to reduce the risk of bad or compromised upstream data triggering incorrect alerts.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
GitHub started flagging malware in npm dependencies before the broader ecosystem expansion. One reference explicitly anchors this npm-only malware coverage to March 2026.
The OpenSSF malicious-packages repository launched in 2023 as a public OSV-format feed for malicious package reports. The repository has since been used to collect community and automated reports across multiple package ecosystems.
GitHub expanded Dependabot malware advisories from npm-only coverage to eight major package ecosystems by ingesting OpenSSF malicious package data into the GitHub Advisory Database. The added coverage includes PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer alongside npm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcegithub.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.