GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

2026-06-11T07:24:19Z0088602e0a6f5ebe0a8df4349c5b54b16f2f7dc5b1162298ada246c66e83c98d
CISA-KEVCheck-PointChrome-V8IoT-botnetJDY-botnetLangflowLinux-kernelLiteLLMMicrosoft-patch-weekPyPIRCEServiceNowVeeamWinRARactive-exploitationgithubnpm-install-scriptsprivilege-escalationsupply-chainzero-day

What happened

A broad set of high-impact security events and fixes: GitHub plans to disable npm install scripts by default to curb supply-chain abuse; the China-linked JDY botnet has grown to 1,500+ SOHO/IoT scanners; multiple vendors (Fortinet, Ivanti, SAP, Veeam, Microsoft, etc.) released patches for critical RCE and information-disclosure flaws; several high-severity vulnerabilities are under active exploitation or have public exploits (Langflow CVE-2026-5027, Chrome V8 CVE-2026-11645, LiteLLM CVE-2026-42271, Check Point CVE-2026-50751, Linux kernel CVE-2026-23111, WinRAR CVE-2025-8088). Supply-chain and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0088602e0a6f5ebe0a8df4349c5b54b16f2f7dc5b1162298ada246c66e83c98d
Enrichment time
2026-06-11T07:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.