GitHub has released npm v12 with major supply-chain protections enabled by default, blocking lifecycle install scripts, implicit node-gyp rebuilds, Git dependencies, and remote URL dependencies unless users explicitly approve them. The change is aimed at reducing install-time code execution abused by recent npm malware campaigns, and introduces an allowlist-style workflow for trusted scripts. GitHub also began phasing out granular access tokens that bypass two-factor authentication: those tokens will lose sensitive account, package, and organization management capabilities starting in August 2026, and are set to lose direct publishing rights in a later phase, with maintainers encouraged to use trusted publishing via OIDC or staged publishing with human 2FA approval instead.
pnpm 11.10 shipped parallel hardening measures focused on preventing credential theft and unsafe build behavior in package workflows. The release adds a structured _auth setting that binds credentials to a specific registry URL and only reads them from global configuration or environment variables, blocking malicious project files such as .npmrc or pnpm-workspace.yaml from redirecting tokens to attacker-controlled hosts. It also stops forwarding upstream registry credentials to install-accelerator servers, restricts pnpm deploy and pnpm pack-app from writing outside the project, prevents repositories from substituting macOS code-signing tools, and fixes a prototype pollution issue involving a dependency named __proto__.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In a later phase scheduled for January 2027, granular access tokens that bypass 2FA will also lose direct publishing capability. GitHub recommended trusted publishing via OIDC or staged publishing with human 2FA approval instead.
GitHub said granular access tokens that bypass two-factor authentication will lose the ability to perform sensitive account, package, and organization management actions starting in early August 2026. This was announced as part of the npm 12 security changes.
pnpm 11.10 was released with a structured _auth setting that binds credentials to specific registry URLs and only reads them from global configuration or environment variables, preventing malicious project files from redirecting tokens. The release also added protections around deploy and pack-app write paths, macOS code-signing tool substitution, prototype pollution via __proto__, and credential forwarding to install-accelerator servers.
npm v12 was released with security-focused defaults that block lifecycle install scripts, implicit node-gyp rebuilds, Git dependencies, and remote URL dependencies unless explicitly approved. The release also introduced an allowlist-style workflow for trusted scripts and kept some stricter configuration checks as opt-in behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourcegithub.blog
Open sourcegithub.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.