npm v12 delivers one of the biggest security improvements in years
ID: 9150fcdf-0331-5c8b-9259-fd9fb7443140
STIX ID: report--9150fcdf-0331-5c8b-9259-fd9fb7443140
Feed Name: Aikido Security's Blog
The report describes npm's planned v12 default to stop running package install scripts, a change intended to block a recent wave of supply-chain postinstall attacks (examples include Nx s1ngularity, Shai-Hulud, the axios hijack, and Mini Shai-Hulud) that used install-time hooks and implicit builds to execute credential stealers, worms, and RATs across hundreds to thousands of packages; it advises upgrading to npm 11.16+/v12, using npm approve-scripts/deny-scripts, restricting git/remote resolution, and adopting tools like Safe Chain to reduce supply-chain infection risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
