← Back

Wire · regulatory

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

Published

10 July 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Geography

United States

Source

Read at thehackernews.com

Verified

Fusion42 · 10 July 2026 · Fusion42 review

npm 12 disables install scripts by default and requires explicit opt-in for dependency lifecycle scripts, Git dependencies, and remote URLs. GitHub also deprecates granular access tokens (GATs) that bypass two-factor authentication, blocking their use for sensitive account and package management actions.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.

◆ The Wire takeaway

If you ship Node.js code, your builds will break until you audit and allowlist your dependencies—and that's the point. This default-off model means your supply chain just got auditable, but you need to move fast: reviewers now see exactly which scripts run, and that visibility becomes a competitive advantage if your competitors stay blind.

Coverage

1 source · 10 Jul 2026

Related on Wire

Topics

CybersecurityEnterprise Softwarenpm-securitydependency-managementsupply-chain-attackdev-tooling2fa-enforcement