logo

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

ID: b7296241-0364-5348-a354-0b850f08fc4e

STIX ID: report--b7296241-0364-5348-a354-0b850f08fc4e

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

npm 12 will disable automatic execution of dependency install scripts by default to mitigate widespread npm supply-chain attacks—such as the mini-shai-hulud worm, the Tanstack incident, and Axios compromises—by requiring explicit allow-listing of packages that need install-time scripts. The change targets the attack vector where compromised package install scripts execute automatically on developer machines and CI, and organizations are advised to audit dependencies, prepare a scripts-allowed whitelist, and review CI/CD configurations before npm 12 ships with Node.js 24 LTS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.