npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
2026-05-24T13:24:14Z•ee4a4dc17fcbfb69d065b4d650b25f8220336bda8c9dbb70a869cc9391a4327f
2faai-securitycisa-kevcomposercredential-stealercritical-exploitationfox-tempestgithubgithub-breachlaravel-langlinux-malwaremalicious-cimalware-signingmegalodonnpmnx-consolepackagistphpproject-glasswingshowboatstaged-publishingsupply-chainvs-code-extensionvulnerability-disclosurewebworm
What happened
A cluster of high-impact supply-chain and exploited vulnerabilities dominated recent reporting: npm added staged publishing with 2FA to curb malicious releases as Packagist and multiple PHP (Laravel‑Lang) packages were backdoored to deliver Linux malware and credential stealers. Large automated attacks and repository compromises were observed — Megalodon injected malicious CI workflows into over 5,500 GitHub repos, and a poisoned Nx Console VS Code extension led to exfiltration of 3,800+ internal GitHub repositories. Multiple high-severity/actively exploited CVEs were disclosed or added to CIS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ee4a4dc17fcbfb69d065b4d650b25f8220336bda8c9dbb70a869cc9391a4327f
- Enrichment time
- 2026-05-24T13:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.