CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

GitHub delays version updates so malware gets caught first

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3233

As cited

Copy frozen at (site build).

threat intel

GitHub delays version updates so malware gets caught first

In September 2025, an attacker compromised npm package maintainer credentials and released malicious versions of widely-used packages including chalk and debug, which collectively receive over 2 billion downloads per week. GitHub responded by implementing a delay in its automated dependency update tool to allow security scanning systems to analyze new releases before the update automation propagates them, reducing the window for malware to spread through automated workflows.

Why it matters: Developers and DevOps teams relying on automated dependency updates need to understand this new delay and adjust their update expectations; this change affects how quickly legitimate updates reach your projects and requires awareness of the new scanning step.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

GitHub delays version updates so malware gets caught first

In September 2025, an attacker compromised npm package maintainer credentials and released malicious versions of widely-used packages including chalk and debug, which collectively receive over 2 billion downloads per week. GitHub responded by implementing a delay in its automated dependency update tool to allow security scanning systems to analyze new releases before the update automation propagates them, reducing the window for malware to spread through automated workflows.

Why it matters: Developers and DevOps teams relying on automated dependency updates need to understand this new delay and adjust their update expectations; this change affects how quickly legitimate updates reach your projects and requires awareness of the new scanning step.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary