- What: npm v12 introduces new security measures to block supply-chain attacks
- Impact: Developers and npm users should update to the new version
Supply chain NPM v12 to block supply-chain attacks with new security measures June 10, 2026 Share By SC Staff (Credit: Araki Illustrations – stock.adobe.com) GitHub announced that npm v12, scheduled for release next month, will implement significant security enhancements designed to prevent supply-chain attacks that exploit the "npm install" command. These changes aim to block malicious activities by requiring explicit approval for actions that were previously automatic, based on information published by Bleeping Computer. The upcoming npm v12 will introduce stricter security protocols for the "npm install" command, a critical step in downloading and installing project dependencies. Previously, scripts like preinstall, install, and postinstall, as well as native module builds and dependencies from Git repositories or remote URLs, executed automatically. Attackers have exploited this by embedding malicious code within these scripts or dependencies. In npm v12, these actions will require explicit developer approval. This change directly addresses common supply-chain attack vectors, including malicious script execution and the abuse of Git dependencies, which have been seen in numerous recent attacks targeting developers and their projects. Developers using these automatic behaviors in their workflows will need to opt-in to continue using them. GitHub recommends upgrading to npm 11.16.0 or newer to receive warnings about upcoming breaking changes, allowing for preparation before the full transition to npm v12. Source: Bleeping Computer SC Staff Related Supply chain Mini Shai-Hulud ‘Hades’ variant affects 23 PyPI package versions Laura French June 10, 2026 The JavaScript stealer payload includes an anti-analysis LLM prompt injection. Supply chain Microsoft investigates breach of open-source projects after malware injection SC Staff June 9, 2026 The compromised projects, many of which are related to Microsoft's Azure cloud service and AI development tools, allowed attackers to steal user passwords and sensitive credentials. Supply chain VS Code adds 2-hour delay for extension updates to combat supply chain threats SC Staff June 8, 2026 Starting with VS Code version 1.123, extensions will undergo a two-hour waiting period after publication before being automatically updated, provided automatic updates are enabled. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds