A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.
A phishing-led campaign is abusing GitHub Releases as a trusted-looking delivery surface for a Python infostealer, turning routine software distribution into a stealth channel for account theft.
A script-led infostealer is using a trusted release channel, a phishing archive, and humanitarian bait to blend into ordinary software traffic.