Organizations are adopting dependency cooldowns to prevent build systems from automatically selecting newly published package versions during a defined waiting period. Semgrep deployed a one-week cooldown across Python projects using uv, causing resolution to choose older eligible releases while registries and the community have time to identify and remove malicious packages. Its rollout required an updated uv version, exemptions for internal or urgently needed packages and registries without reliable publication timestamps, and lockfile validation.
The control addresses supply-chain campaigns in which compromised maintainer credentials and trusted release pipelines distribute malicious updates, including reported Shai-Hulud-related npm activity. Renovate provides a comparable minimumReleaseAge policy for dependency-update workflows; updates remain pending until they meet the age threshold, while security updates bypass the delay. Effective deployment depends on strict handling of missing release timestamps, immutable dependency pinning, curated registries, short-lived OIDC credentials, restricted CI/CD runner egress, and hardened GitHub Actions workflows so a compromised update or pull request cannot seize build credentials.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
On August 4, 2026, the ChainDrop variant allegedly compromised more than 400 packages within four hours through a legitimate signed release pipeline. The poisoned packages received valid SLSA provenance because the campaign abused a compromised authorized maintainer account rather than forging signatures.
By spring 2026, the Mini Shai-Hulud variant had emerged and was targeting credentials associated with Claude, Codex, Cursor, and Gemini.
Shai-Hulud 2.0 allegedly appeared on November 24, 2025, backdooring 796 packages and executing earlier in the installation process. The variant reportedly deleted a user's home directory when it could not obtain credentials or propagate.
Between September 14 and 18, 2025, the Shai-Hulud worm allegedly altered more than 500 npm package versions. It injected a malicious postinstall payload, harvested developer and cloud credentials, and used stolen npm tokens to republish compromised maintainers' packages.
During a migration from Poetry to uv, an incorrect service entry point caused a read-only Kubernetes service to reinstall dependencies at startup and crash when installation failed. Semgrep corrected the entry point to use the image-build virtual environment and added CI testing for the failure mode.
Semgrep began rolling out dependency cooldowns in late March, using uv configuration to prevent recently published package versions from being selected automatically. The rollout used targeted exclusions for internal packages and registries lacking upload timestamps, plus automated lockfile regeneration and validation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcesemgrep.dev
Open sourceblog.yossarian.net
Open sourcedocs.renovatebot.com
Open sourcecooldowns.dev
Open sourcesecuritylab.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.