socket-dev · Crawled Jul 8, 2026

npm v12 Ships With Install Scripts Off by Default, Begins Deprecating 2FA-Bypass Tokens

Read original article ↗

AI Summary

npm v12 introduces security defaults that disable install-time script execution by default, requiring explicit approval for lifecycle scripts, git dependencies, and remote URLs. This change mitigates supply chain attacks like the Miasma 'Phantom Gyp' campaign, which exploited implicit node-gyp rebuilds to run malicious code during installation. The release also begins deprecating 2FA-bypass granular access tokens to reduce risks from compromised accounts. These measures align npm with other package managers and improve resistance to automated malware distribution via dependency installation.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.