Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    September 24, 2026

    Google’s AI Gemini exhibits self-control, stops unauthorised hack into companies

    September 24, 2026

    Meta Pinky Promises Its Smart Glasses Will Be Private Soon

    September 24, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
    Cybersecurity

    npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

    InfoForTechBy InfoForTechMay 23, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananMay 23, 2026Software Supply Chain / DevSecOps

    GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation.

    Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve a package before it is pushed to the npmjs[.]com.

    “Instead of a direct publish that immediately makes a package version available to consumers, the prebuilt tarball is uploaded to a stage queue where a maintainer must explicitly approve it before it becomes installable,” GitHub said.

    The Microsoft-owned subsidiary said the change ensures “proof of presence” for every publish, including those that come from non-interactive CI/CD workflows and trusted publishing with OpenID Connect (OIDC) authentication.

    Before using staged publishing, package maintainers have to meet the following criteria –

    • Have publish access to the package
    • Package already exists on the npm registry, meaning a brand new package cannot be staged
    • 2FA is enabled for the account

    Developers can use the command “npm stage publish” from the root directory of the package to submit it to a staging area. To use this command, it’s essential to update to npm CLI 11.15.0 or newer. For optimal protection, GitHub is recommending that staged publishing be paired with trusted publishing using OIDC.

    A second update focused on npm relates to the introduction of three new install source flags alongside the existing -allow-git flag –

    • –allow-file: Controls installs from local file paths and local tarballs
    • –allow-remote: Controls installs from remote URLs, including https tarballs
    • –allow-directory: Controls installs from local directories

    The flags allow developers to “apply the same explicit-allowlist approach to every non-registry install source,” GitHub said.

    The development comes amid a massive surge in software supply chain attacks targeting open-source ecosystems over the past few months, with one cybercriminal group known as TeamPCP engaging in poisoning popular packages at an unprecedented scale through a self-perpetuating cycle of compromises.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    September 24, 2026

    Weekly Update 522: Live From Oslo with Scott Helme

    September 23, 2026

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    September 23, 2026

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    September 23, 2026

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    September 22, 2026

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

    September 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026381 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views

    Creating an AI Girlfriend with OurDream

    February 12, 202623 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026381 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.