npm v12 Lifecycle Script Limits: A Real Malicious Package Risk Reduction, or Just Moving Risk Around?
ID: ca04ab9c-a08b-5e71-980d-2bf48ee810a9
STIX ID: report--ca04ab9c-a08b-5e71-980d-2bf48ee810a9
Feed Name: Checkmarx Zero
This report analyzes npm v12’s change to block automatic execution of lifecycle scripts by default, explaining that while it reduces one common supply-chain infection vector (preinstall/postinstall scripts), attackers can adapt by moving malicious code to module top-level runtime execution or exploiting developer approval fatigue; it provides examples, mitigation commands (allowScripts/deny-scripts/ignore-scripts), and operational guidance to enforce stricter dependency and CI policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
