npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

2026-05-23T19:24:09Z597687d55641e453260c0f8bf8df1e32b6e2f535875b11f72073f46efa04ef71
active‑exploitationbotnetci/cdcisa‑kevciscocpanelcredential‑stealerdefenderdrupalgithubkernelkimwolflaravel-langlinuxliteSpeedmalware‑signingmegalodonmicrosoftmsaas_disruptionnpmpackagistpoisoned‑extensionshowboatsupply-chainvpn‑takedown

What happened

A wave of high-impact security events: multiple software supply-chain compromises (npm staged publishing controls introduced; Packagist and Laravel‑Lang PHP packages used to deliver Linux binaries and a cross‑platform credential stealer), large-scale GitHub abuses (Megalodon injected malicious CI/CD workflows; a poisoned Nx Console VS Code extension led to exfiltration of internal repos), and active exploitation of several critical vulnerabilities. Notable exploited/linked flaws include LiteSpeed cPanel CVE-2026-48172 (CVSS 10.0), Cisco Secure Workload CVE-2026-20223 (CVSS 10.0), Drupal Core (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
597687d55641e453260c0f8bf8df1e32b6e2f535875b11f72073f46efa04ef71
Enrichment time
2026-05-23T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.