npm is rolling out a preventive security feature for high-impact accounts — those maintaining the registry's most widely used packages. When a sensitive account change is detected (email change or 2FA recovery code use), the account enters a 72-hour read-only state and the previous email is alerted. During this period, package installs and browsing remain available, but publishing, token management, and org/team changes are paused. The safeguard lifts automatically after 72 hours with no action required. This directly addresses a supply chain attack vector where compromised accounts change their email, generate new tokens, and publish malicious packages.

1m read timeFrom github.blog
Post cover image
10.3K Impressions1 Comment