GitHub to Update npm to Thwart Software Supply Chain Attacks
ID: ea080d29-cff4-5cea-96bf-d39000e1b4ec
STIX ID: report--ea080d29-cff4-5cea-96bf-d39000e1b4ec
Feed Name: Infosecurity Magazine (News)
NPM announced npm v12 (effective July 2026) which flips three permissive defaults—blocking install scripts, resolving Git dependencies, and sourcing remote URLs by default—to reduce software supply chain attack risk; developers are advised to upgrade to npm 11.16.0+ for warnings and use npm approve-scripts to create allowlists. Security experts support the structural change but warn attackers may pivot to private registries and that developer friction could lead to blind-approvals or make benign maintainers adopt suspicious workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
