GitHub pulls pin on npm's auto-run scripts
ID: 368a690e-0fb8-523d-96bc-780e9c6a97b0
STIX ID: report--368a690e-0fb8-523d-96bc-780e9c6a97b0
Feed Name: The Register (Security)
Threat Score
GitHub/npm will change defaults to stop running install-time lifecycle scripts automatically (preinstall/install/postinstall) and tighten flags that permit remote or git-based dependencies after exploitation of this vector by malicious packages like the Shai-Hulud worm; the changes aim to reduce the install-time code-execution surface and provide allowlists for approved scripts while acknowledging some packages will require approved exceptions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
