logo

Decoding the GitHub recommendations for npm maintainers

ID: 53597ab0-3368-5e19-8020-b610917252fb

STIX ID: report--53597ab0-3368-5e19-8020-b610917252fb

Feed Name: Datadog Security Labs

Date Published: 2026-01-07

Date Updated: 2026-04-27

...
...

This piece outlines practical steps for npm maintainers to harden package publishing: adopt Trusted Publishing using OIDC to eliminate long‑lived secrets, enforce 2FA for all writes and publishing, and prefer WebAuthn/passkeys or hardware security keys over TOTP, using granular access tokens when automation is required. It explains how these controls reduce the blast radius of leaked credentials, resist phishing/MITM via origin‑bound cryptographic authentication, and what trade‑offs to expect (CI/CD provider limitations, single trusted publisher per package, command‑line/browser flows). The goal is to improve the resilience of the npm supply chain and raise the bar for account compromise across projects and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.