72-Hour Dependency Cooldowns May Create False Security, Experts Warn
A growing number of package managers and platforms, including npm, pnpm, Yarn, and GitHub, adopted 72-hour dependency cooldowns between late 2025 and mid-2026 to guard against supply-chain attacks. However, data from major 2025–2026 malware incidents shows most malicious packages were detected and removed within a median of 14 hours, well before cooldowns expire. Datadog security researcher Kennedy Toomey warned in April 2026 that the measure could backfire, as sophisticated attackers can simply delay malware execution to outlast the cooldown window. Sonatype recorded nearly 395,000 new open-source malware packages in Q4 2025 alone, a 476% surge over the prior three quarters, suggesting time-based gates offer little protection at scale. Critics, including consultancy Evil Martians, argue such policies slow development workflows and foster a false sense of security without delivering meaningful risk reduction.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in