[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-github-widens-malware-alerts-from-npm-to-eight-ecosystems":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},4893,"github-widens-malware-alerts-from-npm-to-eight-ecosystems","GitHub widens malware alerts from npm to eight ecosystems","GitHub now scans PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer for malware, not just npm, via a new OpenSSF data pipeline.","Malicious code hiding in your dependencies just got harder to hide, no matter which language you write in.\n\nGitHub has expanded its Dependabot malware advisories from npm alone to eight ecosystems total: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The company built a single importer that pulls structured reports from OpenSSF's malicious-packages repository, a public database of more than 15,000 entries covering typosquats, dependency-confusion attacks, and hijacked accounts. Because GitHub's own npm advisories already feed into that OpenSSF repo, the importer has to filter out its own reports to avoid re-ingesting them in a loop. GitHub says more than half of the new npm entries each month turn out to be exactly that kind of round-trip.\n\nThis closes a gap that mattered: a Python or Java developer had zero automated warning if a dependency turned out to be stealing credentials, while npm users got flagged the same day. Malware advisories publish automatically without human review, on the logic that hours matter more than nuance when a package is actively exfiltrating data right now.\n\nThat speed is also the risk: GitHub is betting three layers of batch caps, provenance tracking, and one-click rollback are enough to catch a bad automated report before it pages the wrong developer.","[\"dependabot\",\"supply-chain\",\"malware\",\"open-source\"]","2026-08-06T16:51:12.000Z","2026-08-14T06:35:46.376Z","2026-08-14T06:35:58.200Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek lists only six new ecosystems (PyPI, Maven, RubyGems, NuGet, Go, PHP Composer) while the body and 'Eight Ecosystems' headline account for seven (also including crates.io) — add crates.io to the dek so the ecosystem count is consistent across headline, dek, and body.","resolved","security",[32,33,34,35],"dependabot","supply-chain","malware","open-source",[37],{"name":38,"url":39},"GitHub Blog","https:\u002F\u002Fgithub.blog\u002Fsecurity\u002Fsupply-chain-security\u002Fhow-we-took-malware-advisories-beyond-npm\u002F",0,{"sections":42},[43,48,51,56,61,66,71,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",435,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]