npm now freezes high-impact accounts after risky account changes
ID: c4155d12-c23e-5aaf-898f-9ed8d971c621
STIX ID: report--c4155d12-c23e-5aaf-898f-9ed8d971c621
Feed Name: Aikido Security's Blog
The article explains npm’s new 72-hour read-only cooldown for high-impact accounts following sensitive actions (like email changes or 2FA recovery use), motivated by recent supply-chain compromises (axios, Mastra) where attackers used social engineering and a RAT to hijack maintainer accounts and publish malicious releases; it also reviews complementary mitigations (trusted/staged publishing, token reduction, FIDO2), provides guidance for maintainers to monitor email and enable protections, and recommends tools (e.g., Safe Chain) for consumers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
