NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
2026-06-15T07:24:07Z•4bc0fdba50a8be841b22474f9bea915f616177ea87dd48847a702dc5cf8488f7
CVE-2026-35273ai-modelsanthropiccal-waterchrome-149data-breachexport-controlshandalaivanti-sentryjailbreaknpmnpm-12oracleos-command-injectionpatchingpeoplesoftshinyhunterssupply-chain-securityuse-after-freezero-day
What happened
SecurityWeek roundup covering multiple high-impact security developments: Oracle PeopleSoft is linked to active exploitation by ShinyHunters (CVE-2026-35273) with mitigations released; Ivanti Sentry is seeing exploitation attempts for a critical OS command-injection vulnerability that can yield root code execution; Chrome 149 patches 28 vulnerabilities including critical use-after-free bugs. Other notable items: npm 12 will stop executing dependency scripts by default to reduce supply-chain risk; Anthropic temporarily took Fable 5 and Mythos 5 offline due to new export controls and disputed an
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 4bc0fdba50a8be841b22474f9bea915f616177ea87dd48847a702dc5cf8488f7
- Enrichment time
- 2026-06-15T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.