npm v12 delivers one of the biggest security improvements in years
aikido.dev | blog | #supply-chain | #devsecops | #open-source | #malware | #npm | #supply-chain-security | #shai-hulud | #package-registry | #package-manager | #nodejs | #allowlist | #postinstall | #security-defaults | #node-gyp | #install-scripts | #postinstall-scripts
Summary
npm v12 (July 2026) stops running dependency install scripts by default, requiring an allowlist—closing the postinstall vector exploited by Shai-Hulud and Nx, plus stricter git dependency rules.
- Published
- Collected
Skip to content