logo

GitHub pulls pin on npm's auto-run scripts

ID: 368a690e-0fb8-523d-96bc-780e9c6a97b0

STIX ID: report--368a690e-0fb8-523d-96bc-780e9c6a97b0

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

...
...

GitHub/npm will change defaults to stop running install-time lifecycle scripts automatically (preinstall/install/postinstall) and tighten flags that permit remote or git-based dependencies after exploitation of this vector by malicious packages like the Shai-Hulud worm; the changes aim to reduce the install-time code-execution surface and provide allowlists for approved scripts while acknowledging some packages will require approved exceptions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.