JavaScript developers should consider moving away from the npm and yarn platforms , as newly discovered vulnerabilities allow malicious users to carry out worm-like attacks like Shai-Hulud, according to an Israeli researcher. The warning comes from Oren Yomtov of Koi Security , who wrote in a blog post that he discovered six zero-day vulnerabilities in various package managers that could allow hackers to bypass defenses that were proposed last November, following the Shai-Hulud attack on npm . That attack resulted in the compromise of over 700 packages.

npm: What defenses are being bypassed with the new vulnerabilities?
Hackers can bypass the following defenses:
- disabling the ability to run lifecycle scripts, commands that are automatically executed during package installation
- and storing lockfile integrity checks (package-lock.json, pnpm-lock.yaml, and others) in version control (git). The lockfile records the exact version and integrity hash of each package in a dependency tree. On subsequent installations, the package manager checks incoming packages against these hashes, and if something doesn't match, the installation fails. If an attacker compromises a package and pushes a malicious version, the integrity check should detect the discrepancy and prevent it from being installed.
See also: CISA: VMware vCenter vulnerability in KEV Catalog
These recommendations “became the standard advice everywhere from GitHub security guides to company policy documents” after November, “because if malicious code can’t be executed during installation and your dependency tree is pinned, you’re covered.”

November's advice remains valid, but there are some issues
That advice remains valid, Yomtov said. However, the vulnerabilities he discovered —PackageGate— that allow hackers to bypass these two defensesneed to be addressed by all platforms. So far, the pnpm, vlt and Bun platforms have addressed the bypasses, Yomtov said, but npm and yarn have not. Therefore, he recommends that JavaScript developers use pnpm, vlt or Bun.
He added that, in any case, JavaScript developers should keep the JavaScript package manager they use up to date to ensure they have the latest fixes.
GitHub's statement 'disorienting'
Microsoft ,which owns and oversees npm through GitHub, referred questions about the vulnerabilities to GitHub. It said in a statement: “We are actively working to address the newly reported issue, as npm actively scans for malware in the registry.” In the meantime, it is urging project developers to adopt the recommendations in this blog post issued after the Shai-Hulud attacks.
See also: How zero-day exploits are sold on the black market
Also, last September, GitHub said it security npm’s including changes to its authentication and token management. GitHub also warns that if a package installed via git contains a prepare script, its dependencies and devDependencies will be installed. “As we shared when the request was submitted, this is by design and works as expected. When users install a git dependency, they trust the entire contents of that repository, including its configuration files.”
Yomtov found this explanation of intentional design “misleading.” He says the script bypass vulnerability was reported through HackerOne’s bug bounty program on November 26, 2025. While other JavaScript package managers accepted the reports, npm said the platform was working as intended, and that the ‘ignore scripts’ command should prevent unauthorized remote code execution.

“We didn’t write this post to shame anyone,” Yomtov said on the blog. “We wrote it because the JavaScript ecosystem deserves better, and because security decisions should be based on accurate information, not assumptions about defenses that don’t apply. The standard advice, disable scripts and lock your lockfiles, is worth following. But it’s not the full picture,” he said.
See also: HPE Alletra / Nimble Storage: Vulnerability allows privilege escalation
“Until the PackageGate vulnerabilities are fully addressed, organizations must make their own choices about the risk“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
