Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

npm now freezes high-impact accounts after risky account changes

Summary

npm now puts high-impact accounts into a 72-hour read-only freeze after sensitive changes like email swaps or 2FA recovery-code use, alerting the previous email while installs keep working.
Published
Collected

original ↗

Related coverage

back