npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

2026-05-24T13:24:14Zee4a4dc17fcbfb69d065b4d650b25f8220336bda8c9dbb70a869cc9391a4327f
2faai-securitycisa-kevcomposercredential-stealercritical-exploitationfox-tempestgithubgithub-breachlaravel-langlinux-malwaremalicious-cimalware-signingmegalodonnpmnx-consolepackagistphpproject-glasswingshowboatstaged-publishingsupply-chainvs-code-extensionvulnerability-disclosurewebworm

What happened

A cluster of high-impact supply-chain and exploited vulnerabilities dominated recent reporting: npm added staged publishing with 2FA to curb malicious releases as Packagist and multiple PHP (Laravel‑Lang) packages were backdoored to deliver Linux malware and credential stealers. Large automated attacks and repository compromises were observed — Megalodon injected malicious CI workflows into over 5,500 GitHub repos, and a poisoned Nx Console VS Code extension led to exfiltration of 3,800+ internal GitHub repositories. Multiple high-severity/actively exploited CVEs were disclosed or added to CIS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ee4a4dc17fcbfb69d065b4d650b25f8220336bda8c9dbb70a869cc9391a4327f
Enrichment time
2026-05-24T13:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.