GitHub is rolling out enhanced security controls for the npm registry after a series of high-profile supply-chain attacks. Key changes include mandatory two-factor authentication, deprecation of legacy tokens, shorter token lifetimes, and the adoption of trusted publishing workflows. These measures aim to mitigate risks from recent incidents that compromised thousands of accounts and packages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub announced new npm security measures including stronger authentication requirements for publishers, expanded use of access tokens, and policy changes aimed at reducing phishing, account takeover, and malicious package publication. Multiple reports describe the move as a response to rising npm-focused attacks and the Shai-Hulud incident.
A supply-chain campaign dubbed Shai-Hulud emerged in the npm ecosystem, using malicious packages and related compromise activity that raised concern about software publishing security. Coverage describes it as a catalyst for broader scrutiny of npm account protection and package release integrity.
8 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcereversinglabs.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.