Skip to content

Dynatrace Adds Malicious Package Detection to Its Vulnerability Feed

Dynatrace is folding malicious package detection into its Runtime Vulnerability Analytics feed, treating harmful packages as an active threat, not a risk to assess.

Dynatrace vulnerability prioritization dashboard listing 374 detected vulnerabilities with Davis Security Score severities
Credit: Dynatrace

Dynatrace added malicious package detection to its Runtime Vulnerability Analytics feed, treating software built to attack rather than merely to fail as an active threat instead of a risk to triage later.

The distinction matters because it changes the clock. A vulnerability is a weakness that only turns dangerous once an attacker finds and exploits it, which leaves defenders a window to patch first. A malicious package skips that window: the damage, stolen credentials, a planted backdoor, exfiltrated data, happens the instant the code installs and runs. Dynatrace's argument is that treating the two the same, which is how most vulnerability scanners still operate, buries a live attack in a queue built for hypothetical ones.

The expanded feed folds in curated intelligence from OSV.dev and the OpenSSF Malicious Packages project across six ecosystems: Java, JavaScript, Python, Go, .NET, and PHP, per Dynatrace. Dynatrace tags every malicious record with CWE-506, the MITRE classification for embedded malicious code, and assigns it a default critical CVSS 4.0 score of 9.3. Dynatrace SaaS gets the change automatically when version 1.343 rolls out in July 2026; Managed customers need the same update to see it.

What Dynatrace is pitching as the differentiator is context, not coverage: a list of known-bad packages only matters once you know which of them are actually loaded and executing in a given environment. That's the same runtime data Dynatrace already collects for ordinary vulnerability triage, so a malicious package now shows up in the dashboards a team already watches instead of a separate feed nobody checks.

The bigger question is timing. Most supply chain attacks exploit the gap between when a malicious package is published and when anyone notices, and Dynatrace is betting that runtime visibility, not a longer denylist, is what actually narrows it.

Share this story

Stefan Holloway

Stefan Holloway covers programming languages, open-source ecosystems, and the CI/CD and API tooling that ships software for techshooked. He writes reproducibility-first, stating the version tested, showing the configuration, and separating a genuine workflow improvement from release-note marketing.