Back to overview
Resolved

Resolved: Delayed package scan results

Aug 10, 2026 at 11:46pm UTC
Affected services
JavaScript Libraries

Resolved
Aug 11, 2026 at 11:46pm UTC

The malware scan backlog has been fully processed. All packages have completed their initial scans and are now available as expected.

If you are experiencing issues with a specific package, please reach out to our support team.

Thank you for your patience while we completed this work.

Updated
Aug 11, 2026 at 2:17pm UTC

The malware scan backlog continues to drain and is in its final stage. The vast majority of packages have completed scanning and are available as expected. A small number of remaining packages are being re-processed and we expect them to clear shortly.

We will continue to provide updates as the work progresses.

Updated
Aug 11, 2026 at 8:59am UTC

Malware scan is ongoing currently. Until a package's scan completes, requests for it may fail or return MALWARESCANPENDING. We expect this process to take around few more hours. We'll keep this page updated.

Updated
Aug 11, 2026 at 6:03am UTC

95% of malware scan has completed. Until a package's scan completes, requests for it may fail or return MALWARESCANPENDING. We expect this process to take approximately 3 more hours.

Updated
Aug 11, 2026 at 2:52am UTC

We have deployed fixes for the underlying issue, and remaining impact is limited to a backlog of pending malware scans. Until a package's scan completes, requests for it may fail or return MALWARESCANPENDING. We expect this process to take approximately 3 more hours.

Separately, a small number of packages were incorrectly flagged and blocked by malware scanning, i.e., false positives. We are reviewing and unblocking these; if a specific package remains blocked or unavailable for you, please open a support ticket.

Created
Aug 10, 2026 at 11:46pm UTC

We've identified an issue affecting the timing of malware scan completion for some upstream packages, which may cause download errors (MALWARESCANPENDING) for a subset of packages. We've found no evidence that any customer has downloaded a package later confirmed to be malicious. We've increased scanning capacity and deployed a fix to staging, and are working to fully resolve the backlog. We'll post updates as we have them.