Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    August 4, 2026

    ‘DO NOT MENTION ALPR USAGE’: How Cops Are Trying to Hide Their Use of Flock

    August 4, 2026

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»GitHub announces npm security changes to tackle supply-chain attacks
    News

    GitHub announces npm security changes to tackle supply-chain attacks

    adminBy adminJune 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    NPM

    GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the ‘npm install’ command.

    ‘npm install’ is the command used to download and install a project’s dependencies and run any install-related scripts defined by the packages.

    Developers execute it after cloning a project, pulling updates, or during CI/CD builds, and attackers target it because of the potential for automated code execution during package installation.

    image

    The main theme of the announcement is that code execution and non-registry dependency sources that currently trigger automatically during npm install will now require explicit approval instead of being trusted by default.

    Specifically, GitHub announced the following changes:

    1. Starting in version 12, npm install will not run preinstall, install, or postinstall scripts from dependencies unless they have been explicitly approved. This also applies to native module builds triggered through node-gyp, and prepare scripts from Git, local file, and linked dependencies.
    2. npm install will no longer fetch dependencies from Git repositories, whether direct or transitive, unless explicitly permitted. GitHub says this removes a code execution path where a Git dependency’s .npmrc file could alter which Git executable is used, even when install scripts are disabled.
    3. Dependencies installed from remote URLs, such as HTTPS tarballs, will no longer be resolved unless explicitly permitted. This applies to both direct and transitive dependencies.

    These changes can significantly reduce supply-chain attacks by removing the automatic execution of dependency installation scripts, the automatic resolution of Git-based dependencies, and the automatic resolution of remote URL dependencies.

    The new defaults could have disrupted several attack techniques used in recent supply-chain attacks.

    This includes malicious preinstall/postinstall script campaigns targeting eslint-config-prettier, Toptal’s Picasso packages, dozens of data-stealing npm packages, as well as Git dependency abuse documented in Shai-Hulud attacks.

    Projects that rely on any of these behaviors for legitimate workflows will need to explicitly opt in before upgrading to npm v12.

    GitHub recommends that developers prepare by upgrading to npm 11.16.0 or newer, which displays warnings on all actions that will break under version 12.

    This allows developers running their normal install routines to review these warnings and identify dependencies or workflows that will require explicit approval before upgrading.

    After upgrading to version 12, only explicitly approved scripts and dependency sources will continue functioning automatically.

    A community discussion has been opened for developers to share their suggestions on the upcoming changes.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-35273 | THREATINT
    Next Article SSA-346262 V3.3 (Last Update: 2024-07-09): Denial of Service Vulnerability in SNMP Interface of Industrial Products
    admin
    • Website

    Related Posts

    News

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    August 4, 2026
    News

    ‘DO NOT MENTION ALPR USAGE’: How Cops Are Trying to Hide Their Use of Flock

    August 4, 2026
    News

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    August 4, 2026

    ‘DO NOT MENTION ALPR USAGE’: How Cops Are Trying to Hide Their Use of Flock

    August 4, 2026

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.