[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVoq3rUn9W3nxdxomuCS5khm2apFUf6vzcWIwrQzEytw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"240c30e3-ec0b-4bae-a2ba-fe7cf038c68c","npm-12-addresses-automatic-script-execution-vulnerability-in-package-dependencies","f04a782a-8759-45f9-b163-259170cfda5b","NPM 12 Addresses Automatic Script Execution Vulnerability in Package Dependencies","The automatic execution of scripts during npm package installation created a dangerous attack vector that malware like Shai-Hulud exploited to compromise systems. By automatically running code from untrusted dependencies, developers unknowingly gave malicious packages the ability to execute arbitrary commands on their systems. NPM 12's change to require explicit approval for script execution represents a critical shift toward secure-by-default behavior. This highlights the broader risk of trusting third-party code without proper vetting and the importance of implementing least-privilege principles in development workflows.","**Immediate actions:**\n- Update to NPM 12 when released and review script execution policies for existing projects\n- Audit current dependencies and remove unused or untrusted packages\n- Implement package signing verification and use only trusted registries\n\n**Long-term improvements:**\n- Establish a software bill of materials (SBOM) tracking process for all dependencies\n- Create approval workflows for adding new dependencies to projects\n- Implement automated dependency scanning tools with vulnerability alerts\n\n**Detection measures:**\n- Monitor package installation logs for suspicious script execution attempts\n- Set up alerts for new dependencies added to production systems\n- Regularly scan for known vulnerable packages using security tools",[12,13,14,15,16],"CIS Control 2.1","NIST SP 800-161","NIST SSDF PW.4.1","ISO 27001 A.14.2.1","OWASP SCVS","published","2026-06-13T16:20:14.359921+00:00","2026-06-13T16:20:14.151+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.securityweek.com\u002Fnpm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks\u002F","npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks-5a22eb","NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"b78eb2f3-f24b-43c6-a61d-10fa0473b28c","2026-06-14","morning","ThreatNoir Weekend Brief — June 14","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-14\u002Fthreatnoir-morning-brief-2026-06-14.mp3"]