← Back

Wire · regulatory

npm Closes Skeleton-Key Attack Surface: Bypass Tokens Lose Account Control

Published

2 August 2026

Topic

regulatory

Sectors

Developer Tools

Geography

United States

Source

Read at techtimes.com

Verified

Fusion42 · 2 August 2026 · Fusion42 review

GitHub has restricted npm granular access tokens configured to bypass two-factor authentication from performing sensitive account and organizational administrative actions, effective July 31, 2026. This change breaks a critical attack chain that previously allowed total account takeover from a single stolen token.

This Wire brief sits within Fusion42's coverage of Developer Tools.

◆ The Wire takeaway

Your npm automation can no longer rely on bypass-2FA tokens for administrative operations. Rotate tokens now and audit CI environments to prevent an attacker from gaining persistent control.

Coverage

1 source · 2 Aug 2026

Related on Wire

Topics

Developer Toolsnpmsecuritytwo-factor-authenticationtoken-restrictiongithubsupply-chain