NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

2026-06-13T19:24:04Ze6bcb44a7facc05cd987a62bbab087450950974fccdddb10016311955caf661a
ai-modelsanthropiccal-waterchromecommand-injectioncve-2026-35273data-breachexport-controlshandalahoneypotsivantijailbreaknpmoraclepackage-managerpatchpeoplesoftscript-executionsentryshinyhunterssupply-chainuse-after-free

What happened

This collection summarizes multiple active security developments: npm 12 will stop executing dependency scripts by default to reduce supply-chain risk; Anthropic pulled its latest models (Fable 5, Mythos 5) offline to comply with new export controls and disputed an alleged jailbreak; Oracle PeopleSoft is tied to a zero-day (CVE-2026-35273) reportedly exploited by ShinyHunters, and Oracle has issued mitigations; Ivanti Sentry is seeing exploitation attempts against a critical OS command-injection flaw that enables root code execution (hits observed in honeypots); Chrome 149 fixes 28 bugs, incl.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e6bcb44a7facc05cd987a62bbab087450950974fccdddb10016311955caf661a
Enrichment time
2026-06-13T19:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks · Baitaphish