logo

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

ID: d6addf9e-c231-5491-85df-7a8574130414

STIX ID: report--d6addf9e-c231-5491-85df-7a8574130414

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

**GitHub will disable npm install scripts by default in npm v12 to curb widespread supply-chain attacks that abuse lifecycle hooks; the report outlines past incidents (worms and supply-chain campaigns), the risk of install scripts executing with developer permissions, and recommended developer actions (audit dependencies, --ignore-scripts testing, allow-lists and CI updates).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.