npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
ID: 50e90013-92ac-5cac-804c-fe38446fbd8a
STIX ID: report--50e90013-92ac-5cac-804c-fe38446fbd8a
Feed Name: The Hacker News
GitHub has made staged publishing generally available on npm, requiring a human maintainer to approve package releases via a 2FA challenge before they become installable; the update is intended to provide proof-of-presence for publishes (including CI/CD and OIDC-based workflows). The release also adds three --allow- install-source flags (--allow-file, --allow-remote, --allow-directory) to control non-registry install sources. The article frames these changes as mitigation against a recent surge in software supply-chain attacks and mentions the group TeamPCP as an example of recent package-poisoning activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
