Dynatrace added malicious package detection to its Runtime Vulnerability Analytics feed, treating software built to attack rather than merely to fail as an active threat instead of a risk to triage later.
The distinction matters because it changes the clock. A vulnerability is a weakness that only turns dangerous once an attacker finds and exploits it, which leaves defenders a window to patch first. A malicious package skips that window: the damage, stolen credentials, a planted backdoor, exfiltrated data, happens the instant the code installs and runs. Dynatrace's argument is that treating the two the same, which is how most vulnerability scanners still operate, buries a live attack in a queue built for hypothetical ones.
The expanded feed folds in curated intelligence from OSV.dev and the OpenSSF Malicious Packages project across six ecosystems: Java, JavaScript, Python, Go, .NET, and PHP, per Dynatrace. Dynatrace tags every malicious record with CWE-506, the MITRE classification for embedded malicious code, and assigns it a default critical CVSS 4.0 score of 9.3. Dynatrace SaaS gets the change automatically when version 1.343 rolls out in July 2026; Managed customers need the same update to see it.
What Dynatrace is pitching as the differentiator is context, not coverage: a list of known-bad packages only matters once you know which of them are actually loaded and executing in a given environment. That's the same runtime data Dynatrace already collects for ordinary vulnerability triage, so a malicious package now shows up in the dashboards a team already watches instead of a separate feed nobody checks.
The bigger question is timing. Most supply chain attacks exploit the gap between when a malicious package is published and when anyone notices, and Dynatrace is betting that runtime visibility, not a longer denylist, is what actually narrows it.













