npm malware advisories can lag up to 95 days behind package publication, study finds
A analysis of the 100 most recent npm malware advisories from the GitHub Advisory Database found that while most malicious packages are flagged on the same day they appear, 30% remained on the registry for more than a day before an advisory was issued. The worst case, a package called unifi-credential-server, was publicly available for 95 days before being flagged. Researchers used two public APIs — GitHub's advisory feed and the npm registry — to compare each package's publication date against its advisory date. Despite the lag, 95% of the flagged packages were under 30 days old when the advisory arrived, suggesting most npm malware is relatively new when detected. The findings highlight a structural blind spot in advisory-based dependency scanners, which cannot warn users about threats that have not yet been reported.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in