logo

The Pros and Cons of NPM v12's Security Improvements

ID: 2e68da3d-1955-5f01-9365-dd510ae4de96

STIX ID: report--2e68da3d-1955-5f01-9365-dd510ae4de96

Feed Name: OpenSourceMalware Blog

Date Published: 2026-06-10

Date Updated: 2026-06-20

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

The blog analyzes NPM v12's security changes — flipping dangerous defaults for install scripts, requiring explicit flags for git and remote dependencies — and explains why, despite being a positive step, these changes will not eliminate supply-chain risk. It warns that legitimate packages and native builds rely on install-time scripts and that denied defaults may train developers to approve scripts reflexively, while attackers will relocate malicious behavior to less-visible installation paths (CDNs, external scripts) making detection harder; it also highlights cooldowns and package firewalls as useful mitigations and urges teams to inventory dependencies, understand threats, and allocate time for supply-chain security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.