07/31/2026 | Press release | Distributed by Public on 07/31/2026 12:55
Dynatrace malicious package detection identifies intentionally harmful software dependencies at runtime, supporting teams to detect and remove active attacks.
Software supply-chain attacks have moved from edge case to everyday reality. Attackers are no longer content to wait for a vulnerability they can exploit in one of your dependencies - increasingly, they publish packages that are malicious by design and rely on unsuspecting developers to pull them in and run them. By extending coverage of malicious package detection to the Vulnerability Feed, Dynatrace Runtime Vulnerability Analytics (RVA) helps you prioritize and act on threats based on what is actually running in your environment.
It's worth being precise about the difference between a vulnerability and an attack, because the distinction changes how you respond.
A vulnerability is a weakness. It only becomes a real threat when an attacker actively exploits it - which means there's often time to react. On the other hand, the moment a malicious package is installed and its code runs, it does whatever the attacker has instructed it to do: steal credentials, open a backdoor, exfiltrate data, or hijack computing resources. There is no weakness to exploit - running the package is the exploit.
This distinction matters for prioritization. A malicious package in your environment isn't a risk to assess - it's an active threat that must be removed.
| Vulnerability | Malicious package | |
| Description | Software weakness | Intentional attack |
| Trigger | Requires exploitation | Executes immediately |
| Risk type | Potential risk | Active threat |
| Required response | Assess and prioritize | Remove immediately |
Dynatrace is expanding its coverage of malicious package records in the Dynatrace Vulnerability Feed. Alongside your existing vulnerability data, curated data from OSV.dev and the OpenSSF Malicious Packages project are also integrated into the analysis.
Package coverage spans the same six programming ecosystems covered by the Dynatrace vulnerability feed:
Every malicious package record is built to fit naturally into the workflows you already use:
Knowing a malicious package exists somewhere in a registry is useful. Knowing it's running in your environment right now is what allows you to act with confidence.
By expanding coverage of malicious packages in RVA, you don't just get another threat list - you get malicious packages evaluated against what's actually loaded and executing in your applications (Figure 1).
Figure 1. Malicious package detection in the Dynatrace Vulnerabilities appThat means your teams can cut through the noise and focus on genuine exposure rather than working through theoretical inventories, and they can triage and remediate in the same place where they already manage vulnerabilities.
Malicious package detection is delivered as part of the Dynatrace Vulnerability Feed and appears automatically in the Vulnerabilities app - no additional configuration required.
Software supply-chain attacks increasingly rely on malicious packages published directly to public repositories. These attacks exploit the time gap between when a package is published and when it is detected.
With malicious package detection in Runtime Vulnerability Analytics, that vulnerability gap closes.
You no longer rely on discovering threats after the fact. Instead, malicious components are surfaced exactly where your team is already looking - within runtime context - supporting faster remediation decisions for identified malicious packages.
Try the Dynatrace malicious package detection in our Playground and see how threat-aware, curated vulnerability intelligence helps you cut through noise and focus on real risk.
Explore the product hands-on in a live environment, and discover how Dynatrace can accelerate vulnerability prioritization and remediation across your stack - start in the Playground today.