Wire · regulatory
npm Closes Skeleton-Key Attack Surface: Bypass Tokens Lose Account Control
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 2 August 2026 · Fusion42 review
GitHub has restricted npm granular access tokens configured to bypass two-factor authentication from performing sensitive account and organizational administrative actions, effective July 31, 2026. This change breaks a critical attack chain that previously allowed total account takeover from a single stolen token.
This Wire brief sits within Fusion42's coverage of Developer Tools.
◆ ◆ The Wire takeaway
Your npm automation can no longer rely on bypass-2FA tokens for administrative operations. Rotate tokens now and audit CI environments to prevent an attacker from gaining persistent control.
◆ Coverage
1 source · 2 Aug 2026
◆ Related on Wire
◆ Topics