logo

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

ID: 50e90013-92ac-5cac-804c-fe38446fbd8a

STIX ID: report--50e90013-92ac-5cac-804c-fe38446fbd8a

Feed Name: The Hacker News

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: [email protected] (The Hacker News)

...
...

GitHub has made staged publishing generally available on npm, requiring a human maintainer to approve package releases via a 2FA challenge before they become installable; the update is intended to provide proof-of-presence for publishes (including CI/CD and OIDC-based workflows). The release also adds three --allow- install-source flags (--allow-file, --allow-remote, --allow-directory) to control non-registry install sources. The article frames these changes as mitigation against a recent surge in software supply-chain attacks and mentions the group TeamPCP as an example of recent package-poisoning activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.