top of page

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

  • Writer: Joseph K
    Joseph K
  • Aug 16
  • 1 min read

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now draw on all eight ecosystems the moment a user turns malware alerts on. Dependabot itself already runs across more than 30 million repositories and 34-plus package ecosystems overall, which gives a sense of the scale the malware pipeline now has to operate at.






Comments


Recent Posts
Headquarters

1100 106th Avenue NE, Suite 101F
Bellevue, WA 98004
425-998-8505

info@fiduciarytech.com

Seoul Office

Address: Geunshin Building 506-1, 20 Samgae-ro, Mapo-gu, Seoul, 04173, Republic of Korea
02-71
2-2227

info@fiduciarytech.com

fiduciary technology consulting

© 2026 by Fiduciary Technology Solutions 

bottom of page