SECURITYTHE HACKER NEWS
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub is introducing breaking changes in npm version 12 to disable install scripts by default, aiming to prevent supply chain attacks. The update targets malicious code execution via npm lifecycle hooks during the 'npm install' command.
Mentioned
Related Signal
Adjacent reporting
- GitHub announces npm security changes to tackle supply-chain attacks
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools