Skip to content
The Nexus
SECURITYJun 11 · 06:23 UTCTHE HACKER NEWS[email protected] (The Hacker News)

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

GitHub is introducing breaking changes in npm version 12 to disable install scripts by default, aiming to prevent supply chain attacks. The update targets malicious code execution via npm lifecycle hooks during the 'npm install' command.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks · The Nexus