megachangelog
Security

npm adds preventive account protection for high-impact accounts

npm now enables a temporary preventive safeguard for high-impact accounts that control the registry's most widely used packages. This strengthens protection against account-takeover attacks by detecting sensitive account changes.

npm now adds a temporary, preventive safeguard for high-impact accounts—those responsible for the registry’s most widely used packages—whenever it detects a sensitive account change, strengthening protection against account-takeover attacks.

When a high-impact account changes its email or uses a 2FA recovery code, the account is placed into a 72-hour read-only state and an alert is sent to the account’s previous email address. This closes an attack vector that recent supply chain attacks have exploited: a compromised account changes its email, mints a new token, and publishes malicious versions.

During the read-only period, you can still install and download packages, view your organizations and teams, and browse account and package settings.

Actions that could affect the registry or the account’s security—such as publishing, managing tokens, changing package visibility, or modifying org and team membership—are paused until the safeguard lifts.

No action is needed to restore full access: the account returns to normal automatically after 72 hours, with no re-confirmation step. Packages stay fully available to everyone who depends on them throughout.

If you believe your account was affected unexpectedly or you need assistance during a read-only period, contact npm Support.

social

The post npm adds preventive account protection for high-impact accounts appeared first on The GitHub Blog.

npmsecurityaccount-protectionauthentication

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →