
npm has announced a security update that restricts the use of granular access tokens configured to bypass two-factor authentication (2FA). These tokens will no longer be able to perform sensitive actions such as account management or package configuration without an interactive 2FA challenge. This change addresses a major security vulnerability that allowed attackers to exploit leaked tokens. By January 2027, these tokens will also lose direct publishing capabilities, requiring 2FA approval for actions. This update is part of npm's ongoing efforts to enhance security and reduce credential-based attack risks.
Read original
© The AI Daily BriefSam Altman visited Washington to discuss AI model releases and safety testing.