<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/zkzBoiZhC" -->

---
title: npm adds preventive account protection for high-impact...
description: npm is rolling out a preventive security feature for high-impact accounts — those maintaining the registry&#x27;s most widely used packages. When a sensitive...
canonical: https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: npm adds preventive account protection for high-impact accounts | daily.dev
og:description: npm is rolling out a preventive security feature for high-impact accounts — those maintaining the registry&#x27;s most widely used packages. When a sensitive...
og:url: https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc
og:image: https://api.daily.dev/og/posts/zkzBoiZhC.png
og:image:alt: npm adds preventive account protection for high-impact accounts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# npm adds preventive account protection for high-impact accounts

**[GitHub Changelog](https://daily.dev/sources/github_updates)** · 1 min read · 3 upvotes · 1 comments

## Summary

npm is rolling out a preventive security feature for high-impact accounts — those maintaining the registry's most widely used packages. When a sensitive account change is detected (email change or 2FA recovery code use), the account enters a 72-hour read-only state and the previous email is alerted. During this period, package installs and browsing remain available, but publishing, token management, and org/team changes are paused. The safeguard lifts automatically after 72 hours with no action required. This directly addresses a supply chain attack vector where compromised accounts change their email, generate new tokens, and publish malicious packages.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.blog/changelog/2026-06-25-npm-adds-preventive-account-protection-for-high-impact-accounts>

## Questions this post answers

### What happens on npm when a high-impact account changes its email or uses a 2FA recovery code?

The account is placed into a 72-hour read-only state, and an alert is sent to the account's previous email address. During this period, publishing, token management, package visibility changes, and org or team membership modifications are paused, though installing, downloading, and browsing settings remain available. Access returns automatically after 72 hours with no re-confirmation needed.

_Maintainers safeguarding widely used npm packages can follow security changes like this via daily.dev._

### Why did npm add a 72-hour read-only lock after account email changes?

It closes an attack vector used in recent supply chain attacks, where a compromised high-impact account changed its email, minted a new publish token, and pushed malicious package versions. By freezing publishing and token actions for 72 hours after such a sensitive change, npm prevents attackers from immediately weaponizing a hijacked account, while packages stay available to existing dependents throughout.

_Developers tracking npm supply chain security can follow protections like this on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@rahulkumar23** · 0 upvotes

> Nice

## Similar posts on daily.dev

- [npm now freezes high-impact accounts after risky account changes](https://daily.dev/posts/npm-now-freezes-high-impact-accounts-after-risky-account-changes-k0mcnquls) · Aikido Security · 3 upvotes · 0 comments
- [GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing](https://daily.dev/posts/github-hardens-npm-and-actions-defaults-drawing-debate-over-delays-versus-signing-velrggpfa) · InfoQ · 0 upvotes · 0 comments
- [Restricting npm bypass-2FA granular access tokens](https://daily.dev/posts/restricting-npm-bypass-2fa-granular-access-tokens-vh2dwd8rj) · GitHub Changelog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"npm adds preventive account protection for high-impact accounts","url":"https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc"},"datePublished":"2026-06-25T16:22:42.517Z","dateModified":"2026-09-13T18:24:26.774Z","description":"npm is rolling out a preventive security feature for high-impact accounts — those maintaining the registry's most widely used packages. When a sensitive...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/130b3bca59caa9a1837c28072eef0242?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/130b3bca59caa9a1837c28072eef0242?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"GitHub Changelog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"GitHub Changelog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/15004b7835da4d89b02b115871f0f6dc","url":"https://daily.dev/sources/github_updates"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,authentication,npm","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"GitHub Changelog","item":"https://daily.dev/sources/github_updates"},{"@type":"ListItem","position":3,"name":"npm adds preventive account protection for high-impact accounts"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc","comment":[{"@type":"Comment","text":"Nice","datePublished":"2026-06-29T06:40:23.692Z","url":"https://daily.dev/posts/zkzBoiZhC#c-GxjtkkXzh","author":{"@type":"Person","name":"Rahul Kumar","url":"https://daily.dev/rahulkumar23","image":"https://media.daily.dev/image/upload/s--qVHREbAq--/f_auto/v1759385623/avatars/avatar_U27QLhICCvm4in2e75Blh?_a=BAMAK+ZW0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/npm-adds-preventive-account-protection-for-high-impact-accounts-zkzboizhc#faq","mainEntity":[{"@type":"Question","name":"What happens on npm when a high-impact account changes its email or uses a 2FA recovery code?","acceptedAnswer":{"@type":"Answer","text":"The account is placed into a 72-hour read-only state, and an alert is sent to the account's previous email address. During this period, publishing, token management, package visibility changes, and org or team membership modifications are paused, though installing, downloading, and browsing settings remain available. Access returns automatically after 72 hours with no re-confirmation needed. Maintainers safeguarding widely used npm packages can follow security changes like this via daily.dev."}},{"@type":"Question","name":"Why did npm add a 72-hour read-only lock after account email changes?","acceptedAnswer":{"@type":"Answer","text":"It closes an attack vector used in recent supply chain attacks, where a compromised high-impact account changed its email, minted a new publish token, and pushed malicious package versions. By freezing publishing and token actions for 72 hours after such a sensitive change, npm prevents attackers from immediately weaponizing a hijacked account, while packages stay available to existing dependents throughout. Developers tracking npm supply chain security can follow protections like this on daily.dev."}}]}
```

