GitHub has announced that it will change its authentication and publishing options “in the near future,” in response to a recent series of supply chain attacks targeting the npm ecosystem (including the Shai-Hulud attack).

The changes include steps to address threats from token abuse and self-replicating malware. Local publishing with two-factor authentication (2FA) will be required, granular tokens will have a limited seven-day lifespan, and trusted publishing, which allows for the ability to securely publish npm packages directly from CI/CD workflows using OpenID Connect (OIDC).
Trusted publishing, in addition to eliminating the need for npm tokens, establishes cryptographic trust by authenticating each publish using short-lived, workflow-specific credentials. These credentials cannot be exported or reused. More importantly, the npm CLI automatically creates and publishes proof of origin for the package.
See also: Cybersecurity: 6 innovative ways to use AI
“ Every package published via trusted publishing includes cryptographic proof of its source and build environment ,” GitHub noted in late July 2025. “ Your users can verify where and how your package was built, increasing trust in your supply chain .”
GitHub: What changes does npm bring for security?
To support these changes, the company said it will implement the following steps:
– Remove old classic tokens.
– Remove 2FA authentication with one-time password (TOTP) and implement FIDO-based 2FA.
– Restrict granular tokens with publishing permissions with shorter expiration.
– Set publishing access to prevent tokens from being used by default, encouraging the use of trusted publishers or local publishing with 2FA enforcement.
– Remove 2FA bypass option for local package publishing.
– Expand eligible providers for trusted publishing.

This development comes a week after a supply chain attack codenamed Shai-Hulud. The attack introduced a self-replicating worm into hundreds of npm packages that scanned developers' machines for sensitive secrets and transferred them to a server controlled by the attacker.
“By combining self-replication with the ability to steal many types of secrets (and not just npm tokens), this worm could have enabled an endless stream of attacks,” said GitHub’s Xavier René-Corail.
See also: Beware! Kawa4096 Ransomware Attacks Multinationals
It is worth noting that security firm Socket reported that it had detected a malicious npm package called fezbox that is capable of harvesting browser passwords using a new steganographic technique. The package is no longer available for download from npm. It has attracted a total of 476 downloads since it was first published on August 21, 2025.
“In this package, the attacker (npm alias janedu; registration email janedu0216@gmail[.]com) executes a payload inside a QR code to steal usernames and passwords from web cookies, within the browser,” said security researcher Olivia Brown.
Fezbox claims to be a JavaScript tool consisting of common utility functions. But, in reality, it contains code to retrieve a QR code from a remote URL, parse the QR code, and execute the JavaScript payload contained in that URL.
See also: Lucid PhaaS with 17,500 Phishing Domains Impersonates 316 Brands
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The payload attempts to read document.cookie, extract username and password information, and transmit the information to an external server via an HTTPS POST request.
“Most apps no longer store literal passwords in cookies, so it’s hard to say how successful this malware would be,” Brown noted. “However, using a QR code to further obfuscate is a creative turn by the attacker. This technique shows how attackers continue to improve their obfuscation techniques and why it’s more important than ever to have a dedicated tool to check your dependencies.”
