logo

GitHub to Update npm to Thwart Software Supply Chain Attacks

ID: ea080d29-cff4-5cea-96bf-d39000e1b4ec

STIX ID: report--ea080d29-cff4-5cea-96bf-d39000e1b4ec

Feed Name: Infosecurity Magazine (News)

Date Published: 2026-06-12

Date Updated: 2026-06-12

...
...

NPM announced npm v12 (effective July 2026) which flips three permissive defaults—blocking install scripts, resolving Git dependencies, and sourcing remote URLs by default—to reduce software supply chain attack risk; developers are advised to upgrade to npm 11.16.0+ for warnings and use npm approve-scripts to create allowlists. Security experts support the structural change but warn attackers may pivot to private registries and that developer friction could lead to blind-approvals or make benign maintainers adopt suspicious workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.