Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

GitHub is finally tightening up security around npm following multiple attacks

Tech Wavo by Tech Wavo
September 24, 2025
in Computers
0




  • GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security
  • Trusted Publishing will expand, and token-based publishing will be restricted by default
  • Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages

Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the security of its platform.

In a blog post, GitHub detailed changes to authentication and publishing, set to go live “in the near future”, with the aim of hardening package publication.

The announcement notes authentication and publishing options will be changed to include local publishing with required 2FA, granular tokens with a seven-day expiration date, and Trusted Publishing.


You may like

Extra authentication and protection

Furthermore, GitHub announced it would deprecate legacy classic tokens, as well as time-based one-time password (TOTP) 2FA, forcing users to migrate to FIDO-based 2FA. It will also limit granular tokens with publishing permissions to a shorter expiration, and set publishing access to disallow tokens by default (this should make users go for trusted publishers or 2FA enforced local publishing).

The option to bypass 2FA for local package publishing will be removed, while the list of eligible providers for trusted publishing will be expanded.

“We recognize that some of the security changes we are making may require updates to your workflows,” GitHub explained.

“We are going to roll these changes out gradually to ensure we minimize disruption while strengthening the security posture of npm. We’re committed to supporting you through this transition and will provide future updates with clear timelines, documentation, migration guides, and support channels.”

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Open source software is crucial in the software development industry, with organizations of all sizes – from enterprises to microbusinesses – tapping into the sea of high-quality code. This also makes it ideal for cybercriminals engaging in third-party and supply-chain attacks.

One example is the recent Shai-Hulud attack, where a self-replicating worm malware infiltrated the npm ecosystem via a compromised maintainer account, and went about stealing all kinds of secrets from software developers.

The attack forced GitHub to remove more than 500 compromised packages, as well as block the upload of new packages containing whatever indicators of compromise were available at the time.

You might also like

Previous Post

Yakuza Kiwami 3 is official, and it’s out next year with a bonus new spinoff game

Next Post

Google launches an AI-powered mood board app, Mixboard

Next Post
Google launches an AI-powered mood board app, Mixboard

Google launches an AI-powered mood board app, Mixboard

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Microsoft adds Anthropic’s AI to Copilot

by Tech Wavo
September 24, 2025
0
Microsoft adds Anthropic’s AI to Copilot
Computers

Microsoft is leaning into its new partnership with OpenAI’s chief rival, Anthropic. Starting Wednesday, the software giant will incorporate Anthropic’s...

Read more

Light Field monitor makes on-screen objects shine differently depending on the viewing angle

by Tech Wavo
September 24, 2025
0
Light Field monitor makes on-screen objects shine differently depending on the viewing angle
Computers

JapanNext's prototype display uses Light Field technology to change how screen objects shineCompany previewed Light Field monitor concept alongside 6K...

Read more

How to build a GTM strategy that actually drives results at Disrupt 2025

by Tech Wavo
September 24, 2025
0
How to build a GTM strategy that actually drives results at Disrupt 2025
Computers

Go-to-market is often where great startups stumble — but it doesn’t have to be. At TechCrunch Disrupt 2025 in San...

Read more

‘I’ve seen it, it’s incredible’: Qualcomm CEO hypes new desktop Android OS that sounds like a genuine game-changer

by Tech Wavo
September 24, 2025
0
‘I’ve seen it, it’s incredible’: Qualcomm CEO hypes new desktop Android OS that sounds like a genuine game-changer
Computers

We heard more details about ChromeOS' Android upgrades at Snapdragon Summit 2025Snapdragon chips will power Chromebooks with the new OSQualcomm’s...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock