Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
npm Enhances Security with 2FA and Install Controls

npm Enhances Security with 2FA and Install Controls

Posted on May 23, 2026 By CWS

GitHub, the Microsoft-owned company, has introduced new security measures for npm to bolster the safety of the software supply chain. These enhancements allow package maintainers to confirm releases before they are publicly accessible, aiming to prevent supply chain attacks.

Implementation of Staged Publishing

A key feature, staged publishing, is now available on npm, requiring maintainers to pass a two-factor authentication (2FA) challenge to authorize a package release. This process involves uploading a prebuilt tarball to a staging queue, where it awaits explicit approval from a maintainer before becoming installable.

According to GitHub, this update ensures proof of presence for every package publication, including those stemming from non-interactive CI/CD workflows and trusted OpenID Connect (OIDC) authentication. Only packages already existing on the npm registry are eligible for staging, and maintainers must have publish access and 2FA enabled on their accounts.

Command Updates and Additional Recommendations

Developers can submit packages to staging using the command ‘npm stage publish’ from the package’s root directory. This requires npm CLI version 11.15.0 or later. GitHub advises combining staged publishing with trusted publishing via OIDC for enhanced security.

Furthermore, npm has introduced three new install source flags: –allow-file, –allow-remote, and –allow-directory, alongside the existing –allow-git flag. These flags enable developers to specifically allow installations from local file paths, remote URLs, and local directories, providing a more granular control over non-registry install sources.

Addressing Increasing Supply Chain Threats

These developments are a response to a notable increase in software supply chain attacks targeting open-source ecosystems. One group, TeamPCP, has been particularly active, compromising popular packages at a significant scale.

With these updates, GitHub aims to fortify npm against such threats, safeguarding the integrity of software packages and maintaining trust within the developer community. As the landscape of cybersecurity evolves, these measures are critical in mitigating risks associated with open-source software development.

By implementing these controls, npm seeks to maintain a secure environment for developers and protect the broader software ecosystem from emerging vulnerabilities.

The Hacker News Tags:2FA, Cybersecurity, DevSecOps, GitHub, NPM, npm CLI, Open Source, OpenID Connect, package install controls, software development, Software Security, software supply chain, Staged Publishing, supply chain attacks, TeamPCP

Post navigation

Previous Post: AI Model Uncovers 10,000 Critical Software Flaws
Next Post: Packagist Supply Chain Breach Targets Eight Packages

Related Posts

Severe Bugs in AI Code Editor Risk System Intrusion Severe Bugs in AI Code Editor Risk System Intrusion The Hacker News
Amazon Kiro Vulnerability Risks Data Exposure Amazon Kiro Vulnerability Risks Data Exposure The Hacker News
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists The Hacker News
Chinese Cyber Threat Targets Southeast Asian Militaries Chinese Cyber Threat Targets Southeast Asian Militaries The Hacker News
NIST Adjusts CVE Handling Amid Rising Submissions NIST Adjusts CVE Handling Amid Rising Submissions The Hacker News
Salesforce Halts Klue App Due to OAuth Token Misuse Salesforce Halts Klue App Due to OAuth Token Misuse The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark