GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
2026-06-11T07:24:19Z•0088602e0a6f5ebe0a8df4349c5b54b16f2f7dc5b1162298ada246c66e83c98d
CISA-KEVCheck-PointChrome-V8IoT-botnetJDY-botnetLangflowLinux-kernelLiteLLMMicrosoft-patch-weekPyPIRCEServiceNowVeeamWinRARactive-exploitationgithubnpm-install-scriptsprivilege-escalationsupply-chainzero-day
What happened
A broad set of high-impact security events and fixes: GitHub plans to disable npm install scripts by default to curb supply-chain abuse; the China-linked JDY botnet has grown to 1,500+ SOHO/IoT scanners; multiple vendors (Fortinet, Ivanti, SAP, Veeam, Microsoft, etc.) released patches for critical RCE and information-disclosure flaws; several high-severity vulnerabilities are under active exploitation or have public exploits (Langflow CVE-2026-5027, Chrome V8 CVE-2026-11645, LiteLLM CVE-2026-42271, Check Point CVE-2026-50751, Linux kernel CVE-2026-23111, WinRAR CVE-2025-8088). Supply-chain and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0088602e0a6f5ebe0a8df4349c5b54b16f2f7dc5b1162298ada246c66e83c98d
- Enrichment time
- 2026-06-11T07:24:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.