<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

GitHub Tightens NPM Security After Major Supply Chain Attacks

GitHub enhances NPM security with mandatory 2FA and expiring tokens to combat recent supply chain attacks like the Shai-Hulud worm.
Content Team

GitHub is implementing stricter security measures for the NPM registry following a series of devastating supply chain attacks over the past three months. The most severe incident involved the Shai-Hulud self-replicating worm, which compromised 195 packages and pushed over 500 malicious versions to the registry last week.

Earlier attacks targeted maintainer Josh Junon's 18 packages (with 2.5 billion weekly downloads) through phishing, and July saw typosquatting attacks on packages with 30 million combined weekly downloads.

GitHub's response includes mandatory two-factor authentication for local publishing, granular tokens expiring after seven days, and trusted publishing that eliminates long-lived tokens. The platform will also deprecate legacy authentication methods and gradually roll out changes to minimize workflow disruption.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo