Vulnerabilità · 108 giorni fa
npm sta spostando l’esecuzione al momento dell’installazione da una fiducia automatica a un’approvazione esplicita. Questo cambia chi si assume il carico: ora i maintainer devono pre-verificare gli script legittimi, perché il percorso di installazione predefinito non li eseguirà più autonomamente.
5 fonti che coprono questa storia
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.
GitHub to Update npm to Thwart Software Supply Chain Attacks
NPM, part of GitHub, announced a new version of the npm package manager with several security improvements, including disabling install scripts
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
RIP npm Postinstall Scripts: npm v12 Kills Auto Script Execution by Default
npm v12 finally kills automatic lifecycle script execution by default, the feature behind nearly every major supply chain attack.
GitHub announces npm security changes to tackle supply-chain attacks
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install' command.
Part of the PlainSec briefing for 2026-06-12