ADVERTISEMENT

NPM receiving major security overhaul in July, but some security pros say it’s not enough

Installing a piece of code from NPM will no longer auto-run malware on the system, and won’t quietly pull malicious code from external repos unless the developer explicitly allows it. But this won’t be enough to stop supply chain attacks where they matter most, as compromised accounts can still ship malicious code.

npm package compromise

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
July 1, 2026 3 min read
Key takeaways:

What is the new NPM still lacking?

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
ADVERTISEMENT
NPM supply chain attack
Image by Cybernews.

ADVERTISEMENT