[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmNt-onP_8WEzzl0nMzRBD6KGsfqrZ8g7T-hDzddBlf8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"ee196c4f-4d3b-4458-8b56-85858b984933","pnpm-closes-token-redirection-flaw-threatening-supply-chain-integrity","5e650c32-81e4-4146-88ab-e7a649386e6a","pnpm Closes Token Redirection Flaw Threatening Supply Chain Integrity","Prior to pnpm 11.10, a weakness in registry authentication allowed authentication tokens to potentially be redirected to malicious hosts, creating a significant supply chain attack vector. Attackers exploiting this flaw could intercept or misuse registry credentials to serve tampered packages to unsuspecting developers and CI\u002FCD pipelines. This matters because compromised package managers can silently inject malicious code into thousands of downstream applications and organizations. The update underscores how foundational tooling in the software development lifecycle must be treated as a critical security surface, not merely a convenience utility.","**Immediate actions:**\n- Upgrade all development and CI\u002FCD environments to pnpm 11.10 or later immediately to eliminate the token redirection vulnerability.\n- Audit existing `.npmrc` and pnpm configuration files to ensure registry URLs are explicitly pinned to trusted, verified hosts.\n- Rotate any registry authentication tokens that may have been exposed or used in environments running vulnerable pnpm versions.\n\n**Long-term improvements:**\n- Enforce the use of private, internal package mirrors or registries with strict allowlisting to reduce exposure to malicious public packages.\n- Integrate software composition analysis (SCA) tools into CI\u002FCD pipelines to continuously monitor third-party dependencies for tampering or known vulnerabilities.\n- Adopt a formal dependency management policy that defines approved package managers, versions, and update cadences across all development teams.\n\n**Detection measures:**\n- Enable detailed logging of all package registry requests within CI\u002FCD pipelines to detect unexpected outbound authentication attempts to unknown hosts.\n- Implement network egress filtering on build environments to alert on or block connections to unapproved registry endpoints.\n- Subscribe to security advisories for core development tooling (pnpm, npm, yarn) to ensure rapid awareness of newly disclosed vulnerabilities.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-218 SSDF: Supply Chain Risk Management (PO.1, PS.1)","NIST SP 800-161: Supply Chain Risk Management Practices","NIST AC-3: Access Enforcement","NIST SI-7: Software, Firmware, and Information Integrity","SLSA Framework: Source and Build Integrity Levels","OWASP Top 10 A06:2021 – Vulnerable and Outdated Components","NIST CSF DE.CM-3: Personnel Activity Monitoring (applied to pipeline activity)","published","2026-07-08T08:22:02.552245+00:00","2026-07-08T08:22:02.415+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fpnpm-11-1-hardens-registry-authentication?utm_medium=feed","pnpm-11-10-hardens-registry-authentication-to-block-token-redirection-ab40b7","pnpm 11.10 Hardens Registry Authentication to Block Token Redirection",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]