Cybersecurity News
Filters
Filtered by tag: dependabot × Clear
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
Matched: cryptocurrency
GitHub has expanded Dependabot's malware detection beyond npm to cover eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The feature alerts developers to malicious dependencies capable of stealing passwords, API keys, cloud credentials, cryptocurrency wallets, and source code, offering broader protection against open-source supply chain attacks.
