megachangelog
Security

Restricting npm bypass-2FA granular access tokens

npm granular access tokens configured to bypass 2FA can no longer perform sensitive account, organization, and package management actions. These operations now require an interactive 2FA challenge for enhanced security.

npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of the largest credential-based attack surfaces on the registry.

This only impacts npm granular access tokens. This does not affect GitHub personal access tokens, GitHub App tokens, or GITHUB_TOKEN in Actions.

What now requires an interactive 2FA challenge

  • Creating or deleting tokens
  • Changing package access, maintainers, or trusted publishing configuration
  • Managing organization/team membership and package grants

An attacker could previously use a leaked 2FA-bypass token to take over an account and mint new tokens, add a maintainer, and more. A token that skips 2FA shouldn’t also be a way to manage your account.

How to prepare

Stop using 2FA-bypass tokens for these operations and perform them interactively (web or CLI) with a 2FA challenge.

Coming next

2FA-bypass tokens will also lose direct publish. Their publishing surface will reduce to reading private packages and staging a publish, which a maintainer approves with 2FA. We are targeting January 2027 for this update. You should move automated publishing to trusted publishing (OIDC) or staged publishing.

This continues the deprecation we announced on July 8. Have questions or a workflow that would be blocked? Tell us in the community discussion.

The post Restricting npm bypass-2FA granular access tokens appeared first on The GitHub Blog.

npmsecurity2fatokensauth

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →