Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Download: a bid to scrap the virtual wall and AI hits Climate Week

    September 24, 2026

    Aerial Cable Systems for Substation Exit Construction

    September 24, 2026

    The Pope’s AI Guy Is Worried About ‘Cartel’ Behavior Among Big Labs

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Download: a bid to scrap the virtual wall and AI hits Climate Week
    • Aerial Cable Systems for Substation Exit Construction
    • The Pope’s AI Guy Is Worried About ‘Cartel’ Behavior Among Big Labs
    • AI Agents Teamed Up to Cheat at Blackjack. Their Collusion Is Getting Harder to Spot
    • Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices
    • The AI Hype Index: AI loves cheating
    • A US-China AI Hotline Won’t Be Ready For a While
    • A congressional representative just proposed killing America’s border tower program
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
    Cybersecurity

    NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 13, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In response to a recent wave of supply chain attacks targeting the NPM ecosystem, GitHub announced that scripts from dependencies will no longer be executed by default.

    Multiple major incidents that occurred over the past several months, mainly associated with TeamPCP and the Shai-Hulud self-replicating worm, have been abusing the default, automatic execution of scripts from dependencies during npm install to infect thousands of developers with malware.

    To better protect users, starting with NPM version 12, which is expected to arrive in July, script execution will be blocked by default, GitHub announced.

    “npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in your project,” the code-sharing platform explains.

    The change will also impact native node-gyp builds, such as packages that have a binding.gyp and no explicit install script, as well as prepare scripts from git, file, and link dependencies. The recent Shai-Hulud Miasma attacks relied on a weaponized binding.gyp file.

    To check how the upcoming change will impact their projects, developers can run npm approve-scripts –allow-scripts-pending, and allow the packages they trust and block the rest, to obtain an allowlist that is written to package.json.

    Advertisement. Scroll to continue reading.

    Once the JSON is committed, developers using NPM version 11.16.0 or above will receive warnings if their install routine executes scripts.

    Additionally, GitHub explains, Git dependencies (direct or transitive) will no longer be resolved at npm install, unless explicitly allowed.

    “This closes a code-execution path where a Git dependency’s .npmrc could override the Git executable, even with –ignore-scripts,” the platform notes.

    Similarly, dependencies from remote URLs will no longer be resolved in NPM version 12. This includes HTTPS tarballs (direct or transitive), but developers can allow them via the –allow-remote flag, which has been available since version 11.15.0.

    “Upgrade to NPM 11.16.0 or later, run your normal install, and review the warnings. Use npm approve-scripts –allow-scripts-pending to see which packages have scripts, approve the ones you trust, and commit the updated package.json. After that, only the scripts you approved keep running once you upgrade,” GitHub notes.

    Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

    Related: Supply Chain Attack Hits 32 Red Hat NPM Packages

    Related: GitHub Confirms Hack Impacting 3,800 Internal Repositories

    Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

    Attacks behavior chain Change Execution npm prevent Script Supply
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Pope’s AI Guy Is Worried About ‘Cartel’ Behavior Among Big Labs

    September 24, 2026

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026

    Innocent-looking AI reasoning can make bad behavior harder to catch

    September 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Download: a bid to scrap the virtual wall and AI hits Climate Week
    • Aerial Cable Systems for Substation Exit Construction
    • The Pope’s AI Guy Is Worried About ‘Cartel’ Behavior Among Big Labs
    • AI Agents Teamed Up to Cheat at Blackjack. Their Collusion Is Getting Harder to Spot
    • Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices

    The Download: a bid to scrap the virtual wall and AI hits Climate Week

    September 24, 2026

    Aerial Cable Systems for Substation Exit Construction

    September 24, 2026

    The Pope’s AI Guy Is Worried About ‘Cartel’ Behavior Among Big Labs

    September 24, 2026

    AI Agents Teamed Up to Cheat at Blackjack. Their Collusion Is Getting Harder to Spot

    September 24, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.