Software Supply Chain
npm Publish-Time Malware Scanning Adds Delay and Dual-Use Disclosure
GitHub says new npm packages will be scanned before installation availability, with a typical short delay and possible review or blocking. The release changes publishing workflow; it does not promise complete malware detection.

What happened and why it matters
A security control at publication time changes release automation as well as detection coverage.
Primary source
Primary reference: GitHub: npm publish-time malware scanning and dual-use metadata. Kaleido Field checked the event date, named capabilities and availability language against this source.
| Source date | July 28, 2026 |
|---|---|
| Checked by Kaleido Field | July 29, 2026, 08:30 CST |
| What this source supports | official registry-policy and workflow update for what changes with npm publish-time malware scanning |
| What it does not prove | It does not prove a universal product ranking, full regional availability, or performance on every visual intelligence task. |
The workflow change
GitHub says a package can be released normally, held for review, or blocked after an automatic scan. It describes a typical delay of about five minutes, with longer delays possible.
Publish automation that assumes instant availability needs to tolerate the new state.
Dual-use disclosure
The changelog introduces a contentPolicy field and a text DISCLOSURE file for packages with legitimate security-relevant capabilities.
A declaration can trigger review; it is not an automatic approval.
The evidence limit
Registry scanning is a defensive layer with false-negative and false-positive tradeoffs. GitHub explicitly describes timing as typical behavior rather than a guarantee.
Consumers should retain ordinary dependency review and incident-response practices.
Evidence boundary
This page reports a dated event from a named primary source. Company specifications and adoption statements remain attributed claims unless independent evidence is cited above.
FAQ
What is the practical answer?
GitHub says new npm packages will be scanned before installation availability, with a typical short delay and possible review or blocking. The release changes publishing workflow; it does not promise complete malware detection.
What source does this article use?
The primary source is GitHub: npm publish-time malware scanning and dual-use metadata. Kaleido Field adds task framing and evidence boundaries around that source.
Where should the user verify the answer?
Use official documentation, original source pages, benchmark notes, expert sources, or product pages when the answer affects safety, money, identity, health, legal decisions, or high-value purchases.