NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
2026-06-13T19:24:04Z•e6bcb44a7facc05cd987a62bbab087450950974fccdddb10016311955caf661a
ai-modelsanthropiccal-waterchromecommand-injectioncve-2026-35273data-breachexport-controlshandalahoneypotsivantijailbreaknpmoraclepackage-managerpatchpeoplesoftscript-executionsentryshinyhunterssupply-chainuse-after-free
What happened
This collection summarizes multiple active security developments: npm 12 will stop executing dependency scripts by default to reduce supply-chain risk; Anthropic pulled its latest models (Fable 5, Mythos 5) offline to comply with new export controls and disputed an alleged jailbreak; Oracle PeopleSoft is tied to a zero-day (CVE-2026-35273) reportedly exploited by ShinyHunters, and Oracle has issued mitigations; Ivanti Sentry is seeing exploitation attempts against a critical OS command-injection flaw that enables root code execution (hits observed in honeypots); Chrome 149 fixes 28 bugs, incl.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- e6bcb44a7facc05cd987a62bbab087450950974fccdddb10016311955caf661a
- Enrichment time
- 2026-06-13T19:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.