GitHub has announced the release of npm version 12, which brings significant changes aimed at enhancing cybersecurity. A key feature of this update is that npm disables install scripts by default to mitigate supply chain risks. This decision reflects a growing concern over the vulnerabilities t…

npm disables security illustration
Photo by Ferenc Almasi on Unsplash

GitHub has announced the release of npm version 12, which brings significant changes aimed at enhancing cybersecurity. A key feature of this update is that npm disables install scripts by default to mitigate supply chain risks. This decision reflects a growing concern over the vulnerabilities that can arise from automated scripts during the installation process. Previously, these scripts would run automatically, potentially compromising user privacy and system integrity.

In npm 12, the allowScripts setting is now turned off by default. This means that users must opt-in to allow scripts to run during installations. This change is particularly important in light of recent attacks that have exploited install scripts to introduce malicious code into projects. By requiring users to consciously enable this feature, npm aims to reduce the risk associated with supply chain vulnerabilities.

Impact of npm Disables on Cybersecurity

The decision to disable install scripts by default is a critical step in enhancing network security across the npm ecosystem. Supply chain attacks have become increasingly prevalent, and they can have devastating effects on both individual developers and larger organizations. When malicious code is injected into a project through compromised scripts, it can lead to data breaches, unauthorized access, and other severe cybersecurity incidents.

By making install scripts opt-in, npm provides developers with greater control over their projects and the dependencies they use. This is particularly relevant for those who rely on third-party packages, which can sometimes include unverified code. Additionally, the deprecation of granular access tokens (GATs), designed to bypass two-factor authentication (2FA), further strengthens the security framework around npm. This move discourages practices that could lead to unauthorized access, reinforcing the importance of proper authentication methods.

For users, this change means they need to be more vigilant when installing packages. They should ensure that they only enable scripts from trusted sources and remain aware of the potential risks associated with third-party dependencies. The npm community is encouraged to adopt best practices for data protection and cybersecurity, including regular updates and monitoring of security advisories.

Context

The move to disable install scripts by default is part of a broader trend in the software development community to prioritize security. As cyber threats evolve, developers and organizations must adapt their practices to protect against increasingly sophisticated attacks. The rise of supply chain vulnerabilities has prompted many software platforms to reconsider their default settings and security measures.

In recent years, several high-profile supply chain attacks have highlighted the risks associated with automated processes in software development. By proactively addressing these issues, npm is taking a significant step towards safeguarding its users and the integrity of the code they work with.

What to do

To ensure your projects remain secure following the release of npm 12, consider taking the following actions:

  • Update all affected software to the latest versions immediately.
  • Enable automatic updates where possible to stay ahead of potential vulnerabilities.
  • Monitor security advisories from npm and other affected vendors.
  • Use a VPN service to protect your internet traffic. Consider reliable options like ProtonVPN or NordVPN.
  • Implement additional security measures such as multi-factor authentication for enhanced protection.

Source

Original article

For more cybersecurity news, reviews, and tips, visit QuickVPNs.

New Providers
Proton VPN Review (2025): The Ultimate Choice for Privacy Purists?

A high-security VPN from the creators of Proton Mail, offering unmatched privacy with Swiss jurisdiction, open-source apps, and a unique Secure Core architecture.

CyberGhost VPN Review (2025): The Best VPN for Streaming & Beginners?

A user-friendly VPN with a massive server network, specialized servers for streaming and torrenting, and an industry-leading 45-day money-back guarantee.

Surfshark Review (2025): The Best-Value VPN for Unlimited Devices?

An incredibly affordable VPN offering unlimited simultaneous connections, a powerful ad blocker, and reliable performance for streaming.

ExpressVPN Review (2025): Still the Best Premium VPN for Speed & Simplicity?

A premium, ultra-fast VPN focused on user-friendliness, with top-tier security, a dedicated router app, and reliable streaming.

NordVPN Review (2025): An Incredible VPN for Speed & Security?

Incredibly fast VPN with audited no-logs policy, advanced Threat Protection, and unmatched streaming capabilities.