NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
ID: b7296241-0364-5348-a354-0b850f08fc4e
STIX ID: report--b7296241-0364-5348-a354-0b850f08fc4e
Feed Name: CosmicBytez Labs
npm 12 will disable automatic execution of dependency install scripts by default to mitigate widespread npm supply-chain attacks—such as the mini-shai-hulud worm, the Tanstack incident, and Axios compromises—by requiring explicit allow-listing of packages that need install-time scripts. The change targets the attack vector where compromised package install scripts execute automatically on developer machines and CI, and organizations are advised to audit dependencies, prepare a scripts-allowed whitelist, and review CI/CD configurations before npm 12 ships with Node.js 24 LTS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
