CYBER● LOWJul 9 · Jul 9, 2026, 4:49 PM
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
The Hacker News
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in - allowScripts defaults to off, meaning
GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.
More in Cyber
CYBERnow[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDark ReadingCYBERnow[Virtual Event] Building a Secure AI Strategy for the EnterpriseDark ReadingCYBER2h agoOpenAI AI agents hack German site in undisclosed incident , use it to coordinate and bypass restrictionsdigit.in · IndiaCYBER3h agoCollege morphing case in Keralam: Police probe if accused student got help from othersThe Hindu