npm now freezes high-impact accounts after risky account changes
aikido.dev | blog | #supply-chain | #open-source | #developer-security | #npm | #social-engineering | #account-security | #supply-chain-security | #2fa | #package-registry | #two-factor-authentication | #registry | #axios | #registry-security | #account-freeze | #cooldown
Summary
npm now puts high-impact accounts into a 72-hour read-only freeze after sensitive changes like email swaps or 2FA recovery-code use, alerting the previous email while installs keep working.
- Published
- Collected
Skip to content