NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

2026-06-15T07:24:07Z4bc0fdba50a8be841b22474f9bea915f616177ea87dd48847a702dc5cf8488f7
CVE-2026-35273ai-modelsanthropiccal-waterchrome-149data-breachexport-controlshandalaivanti-sentryjailbreaknpmnpm-12oracleos-command-injectionpatchingpeoplesoftshinyhunterssupply-chain-securityuse-after-freezero-day

What happened

SecurityWeek roundup covering multiple high-impact security developments: Oracle PeopleSoft is linked to active exploitation by ShinyHunters (CVE-2026-35273) with mitigations released; Ivanti Sentry is seeing exploitation attempts for a critical OS command-injection vulnerability that can yield root code execution; Chrome 149 patches 28 vulnerabilities including critical use-after-free bugs. Other notable items: npm 12 will stop executing dependency scripts by default to reduce supply-chain risk; Anthropic temporarily took Fable 5 and Mythos 5 offline due to new export controls and disputed an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
4bc0fdba50a8be841b22474f9bea915f616177ea87dd48847a702dc5cf8488f7
Enrichment time
2026-06-15T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.