<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🦋 OSV has withdrawn 157 malware reports after automated detections incorrectly flagged npm and PyPI packages as malicious, pushing bad records for trusted projects into OSV-consuming security tools and CI&#x2F;CD systems.]]></title><description><![CDATA[<p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f98b.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--butterfly"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🦋"
      alt="🦋"
    /> OSV has withdrawn 157 malware reports after automated detections incorrectly flagged npm and PyPI packages as malicious, pushing bad records for trusted projects into OSV-consuming security tools and CI/CD systems.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://socket.dev/blog/osv-withdraws-157-malware-reports" title="OSV Withdraws 157 Malware Reports After Automated False Posi...">
<img src="https://cdn.sanity.io/images/cgdhsj6q/production/4a4197a755660c153ff7eac364cfed49c4942b05-2752x1536.jpg?w=1000&q=95&fit=max&auto=format" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://socket.dev/blog/osv-withdraws-157-malware-reports">
OSV Withdraws 157 Malware Reports After Automated False Posi...
</a>
</h5>
<p class="card-text line-clamp-3">OSV withdrew 157 OSV malware reports after automated false positives incorrectly flagged trusted npm and PyPI packages, sending bad records into tools...</p>
</div>
<a href="https://socket.dev/blog/osv-withdraws-157-malware-reports" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://socket.dev/favicon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />









<p class="d-inline-block text-truncate mb-0">Socket <span class="text-secondary">(socket.dev)</span></p>
</a>
</div></p><p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f517.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--link"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🔗"
      alt="🔗"
    /> <a href="https://bsky.app/profile/socket.dev/post/3mmtsbeufhs22" rel="nofollow noopener"><span>https://</span><span>bsky.app/profile/socket.dev/po</span><span>st/3mmtsbeufhs22</span></a></p><p><a href="https://mstdn.feddit.social/tags/Security" rel="tag">#<span>Security</span></a> <a href="https://mstdn.feddit.social/tags/SupplyChain" rel="tag">#<span>SupplyChain</span></a> <a href="https://mstdn.feddit.social/tags/Bluesky" rel="tag">#<span>Bluesky</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/f23fbc8a-f079-4757-bc36-85df066cdb61/osv-has-withdrawn-157-malware-reports-after-automated-detections-incorrectly-flagged-npm-and-pypi-packages-as-malicious-pushing-bad-records-for-trusted-projects-into-osv-consuming-security-tools-and-ci-cd-systems.</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 09:34:39 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/f23fbc8a-f079-4757-bc36-85df066cdb61.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 May 2026 16:41:22 GMT</pubDate><ttl>60</ttl></channel></rss>