logo

GitHub Introduces Automatic Controls to Prevent Malicious npm Install Scripts

ID: fa5c26f2-be9c-555d-bb5f-6545b267cb5f

STIX ID: report--fa5c26f2-be9c-555d-bb5f-6545b267cb5f

Feed Name: GBHackers

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Divya

...
...

GitHub is rolling out security-hardening changes in npm v12 (with opt-in warnings in npm 11.16.0+) that disable dependency install-time scripts by default (allowScripts off), restrict Git and remote tarball dependencies (--allow-git and --allow-remote default to "none"), and add an explicit approve-scripts workflow that records script allowlists in package.json; these measures aim to reduce supply-chain and install-script based attacks and require developers to review and explicitly permit trusted scripts before upgrading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.