The npm is introducing revolutionary security measures by adding mandatory 2FA checks and new tools to protect against attacks in the software supply chain. GitHub, which owns npm, has announced the availability of staged publishing, which requires explicit approval from a maintainer before packages are made publicly available for installation. The move is in response to the explosive increase in cyberattacks targeting open source ecosystems, threatening millions of applications worldwide.

The new staged publishing is a significant security upgrade for npm, requiring a human maintainer to go through a authentication two-factor (2FA) to approve a package before it is published to npmjs.com. Instead of publishing directly, which would make a package version immediately available to consumers, the prebuilt tarball is uploaded to a stage queue where a maintainer must explicitly approve it before it becomes installable. This approach creates a critical checkpoint that can stop malicious packages even if criminals have gained access to automated publishing systems.
Microsoft , through its subsidiary GitHub , emphasized that the change ensures “proof of presence” for every release, including those from non-interactive CI/CD workflows and trusted publishing with OpenID Connect (OIDC) authentication . This measure is aimed at addressing the increasing number of software supply chain attacks that have plagued open source ecosystems in recent months. The importance of this change becomes even more apparent when we consider that npm serves billions of package downloads per month, making it one of the most critical parts of the global digital infrastructure.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted
npm: Staged Publishing Prerequisites and Technical Details
Before using staged publishing, package maintainers must meet specific security criteria:
- They must have publishing rights to the package,
- The package must already exist in the npm (i.e. a completely new package cannot pass the staging phase)
- 2FA must be enabled for their account.
Developers can use the “npm stage publish” from the root directory of a package to submit it to a staging area. This process creates a temporary repository where the package remains until it is approved by an authorized maintainer.
To use this command, you must be updated to npm CLI 11.15.0 or later. For optimal protection, GitHub recommends that staged publishing be combined with trusted publishing using OIDC. This approach significantly reduces the risk of stolen credentials or compromised tokens, as authentication is done through cryptographically secure protocols that do not require long-term secrets to be stored in CI/CD systems.
See also: Google attributes Axios Supply Chain Attack to UNC1069

New Install Source Flags For Enhanced Security
The second major update to npm involves the introduction of three new install source flags alongside the existing –allow-git flag -. The new flags include –allow-file which controls installations from local file paths and local tarballs, –allow-remote which controls installations from remote URLs including https tarballs, and –allow-directory which controls installations from local directories. These flags act as security filters that allow developers to precisely define which sources are considered trustworthy for installing packages.
This way, developers can “apply the same explicit-allowlist approach to every non-registry install source,” as GitHub reported.
The importance of these controls becomes critical in corporate environments where supply chain security is a priority and where even a small breach can have devastating consequences.

Practical Security Tips for Organizations
Cybersecurity experts recommend that organizations adopt a multi-layered security approach to protect against supply chain attacks. For package maintainers, enabling 2FA on all npm and GitHub with publishing permissions is essential, and using passkey-based 2FA is preferred over SMS or less secure methods. Additionally, organizations should use the “Require two-factor authentication and prohibit tokens” setting for critical packages, minimize the number of maintainers with publishing permissions, and periodically review package settings.
See also: GitHub Actions: Supply chain attack steals CI/CD credentials
The development comes amid a huge increase in supply chain attacks targeting open source ecosystems. A criminal group known as TeamPCPhas been involved in infecting popular packages, according to The Hacker News. These attacks have demonstrated the need for more stringent control and verification measures in the package publishing process.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
