• News/
  • https://www.bleepingcomputer.com/news/security/github-tightens-npm-security-with-mandatory-2fa-access-tokens/

GitHub tightens npm security with mandatory 2FA, access tokens

BleepingComputer
·
Bill Toulas
·
Published Sep 23, 2025
·
Updated

GitHub is introducing a set of defenses against supply-chain attacks on the platform that led to multiple large-scale incidents recently. Notable cyberattacks that started from compromising GitHub repositories and then spread to NPM include the "s1ngularity" attack in late August, the "GhostAction" campaign in early September, and the worm-style campaign dubbed "Shai-Hulud" from last week. The attacks led to the compromise of thousands of accounts and private repositories, the theft of sensitive data, and significant remediation costs. Although GitHub responded quickly to minimize the impact of these incidents, the developer platform admits that stronger proactive measures would be more effective. To reduce these risks, GitHub announced that it would gradually implement the following measures: Trusted publishing, already adopted across multiple ecosystems, is strongly encouraged as it eliminates the need to manage API tokens in build systems. NPM maintainers are advised to switch to trusted publishing immediately, as well as to enforce 2FA for publishing and writing, and use WebAuth instead of time-based one-time passwords (TOTP) for 2FA. The code hosting and collaboration platform will roll out these changes gradually and provide the necessary documentation and migration guides to minimize disruption to existing workflows. The announcement also stresses that ecosystem security is a collective duty, and developers are expected to take action themselves to mitigate supply-cha...

Read full article

Affected Software

2 affected components
GitHub GitHub
npm NPM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses GitHub's new security measures requiring two-factor authentication (2FA) and access tokens for npm to prevent supply-chain attacks.

2

What security implications are discussed in the article?

The article highlights the increased risk of supply-chain attacks that can exploit vulnerabilities in GitHub repositories and npm packages.

3

What products or software are affected?

The affected software includes GitHub and npm, both of which are critical for code management and package distribution.

4

Why is GitHub implementing mandatory 2FA for npm?

GitHub is implementing mandatory 2FA for npm to enhance security and protect against unauthorized access and potential attacks.

5

What incidents prompted these security updates?

Recent large-scale cyberattacks that compromised GitHub repositories and spread to npm packages prompted the implementation of these security updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203