Story perspectives
GitHub Boosts npm Security After 500+ Malware Attacks
9/24/2025
1 of 1
Story summary
- The Shai-Hulud worm attack led GitHub to strengthen npm security after exploiting maintainer accounts to spread malware.
- Over 500 compromised npm packages were removed to prevent further damage.
- New npm publishing rules require mandatory two-factor authentication and granular tokens with a seven-day lifespan, while trusted publishing aims to remove static API tokens from build systems.
