[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faquJKZcOPRKmj_jZYOPk8AK4LDCTMdKjvu4Z0Be-mu8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"c2989449-b3f8-4935-a9cb-d9c35c64fb82","npm-v12-hardens-supply-chain-defenses-by-restricting-install-scripts-and-deprecating-2fa-bypass-toke","f9bc348c-b4b6-4b00-b9ae-dc818cdf342f","npm v12 Hardens Supply Chain Defenses by Restricting Install Scripts and Deprecating 2FA-Bypass Tokens","Supply chain attacks via malicious npm packages have exploited the automatic execution of install scripts, allowing attackers to run arbitrary code the moment a developer installs a compromised dependency. The deprecation of 2FA-bypass tokens closes a critical loophole where long-lived automation tokens could circumvent multi-factor authentication protections, enabling attackers with stolen tokens to publish malicious packages without friction. These changes matter because the npm ecosystem serves millions of developers, meaning a single compromised package can cascade into thousands of downstream applications. Secure-by-default configurations are essential because most developers will not manually harden settings, making opt-in security insufficient at scale.","**Immediate actions:**\n- Upgrade to npm v12 immediately to benefit from install scripts being disabled by default and the deprecation of 2FA-bypass tokens.\n- Audit all existing npm automation tokens and revoke any legacy 2FA-bypass tokens still in use across CI\u002FCD pipelines.\n- Review your project's `package.json` dependencies and verify that any packages using install scripts are explicitly trusted before re-enabling script execution.\n\n**Long-term improvements:**\n- Enforce a software composition analysis (SCA) tool in your CI\u002FCD pipeline to automatically flag newly introduced or updated dependencies with suspicious install scripts.\n- Adopt a private npm registry or package proxy (e.g., Artifactory, Verdaccio) to pin approved package versions and prevent unauthorized package substitution attacks.\n- Implement a least-privilege policy for npm publish credentials by using scoped, short-lived tokens with mandatory 2FA rather than persistent automation tokens.\n\n**Detection measures:**\n- Enable npm audit and integrate it into every build pipeline step to continuously detect known vulnerabilities in the dependency tree.\n- Monitor package registries and internal artifact repositories for unexpected new versions or ownership changes on critical dependencies.\n- Establish alerting for any CI\u002FCD pipeline job that attempts to enable install scripts or use deprecated token types, treating these as potential indicators of compromise.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 CM-7: Least Functionality","NIST SSDF PW.4: Reuse Existing, Well-Secured Software","SLSA Supply Chain Levels for Software Artifacts (Level 2+)","OWASP Top 10 A06:2021 – Vulnerable and Outdated Components","published","2026-07-08T22:20:27.100624+00:00","2026-07-08T22:20:26.978+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fnpm-12?utm_medium=feed","npm-v12-ships-with-install-scripts-off-by-default-begins-deprecating-2fa-bypass--f924e3","npm v12 Ships With Install Scripts Off by Default, Begins Deprecating 2FA-Bypass Tokens",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"5173437d-5525-4969-a260-2b1cc1cf5346","2026-07-09","morning","ThreatNoir Morning Brief — July 9","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-09\u002Fthreatnoir-morning-brief-2026-07-09.mp3"]