1. X
  2. npm
Log inSign up
npm
GitHub
4,711 posts
npm profile banner
user avatar

npm

GitHub
@npmjs
The package manager for JavaScript Problems? Visit npmjs.com/support or github.com/npm/feedback
npmjs.com
Joined June 2011
142
Following
147.4K
Followers
RepliesRepliesMediaMedia
  • user avatar
    npm
    GitHub
    @npmjs
    1h
    npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface.
    Image
    Restricting npm bypass-2FA granular access tokens - GitHub Changelog
    From github.blog
  • user avatar
    npm
    GitHub
    @npmjs
    Aug 4
    npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing.
    docs.npmjs.com
    Trusted publishing for npm packages | npm Docs
    Documentation for the npm registry, website, and command-line interface
  • user avatar
    npm
    GitHub
    @npmjs
    Jul 29
    Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default.
    Image
    npm publish-time malware scanning and dual-use metadata - GitHub Changelog
    From github.blog
  • user avatar
    npm
    GitHub
    @npmjs
    Jul 8
    npm v12 is here. npm install now blocks lifecycle scripts, git, and remote-URL dependencies by default — a more secure baseline out of the box. We're also starting to phase out npm 2FA-bypass tokens for account changes and direct publishing. Details 👇
    Image
    npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
    From github.blog
  • user avatar
    npm
    GitHub
    @npmjs
    May 20
    1/ To prevent supply chain attacks following the pattern of Mini Shai Hulud, we invalidated npm granular access tokens with write access that bypass 2FA. Update the stored token and rerun the workflow for your automations.

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement