NPM 12 Will Change Script Execution Behavior to Prevent Attacks
NPM 12 is changing the rules, and AI coding agents are the reason it can't come soon enough For nineteen years, npm install has quietly done something most developers never think about: it executes code. Not just downl
NPM 12 is changing the rules, and AI coding agents are the reason it can't come soon enough
For nineteen years, npm install has quietly done something most developers never think about: it executes code. Not just downloads it runs them automatically via preinstall, install, and postinstall lifecycle hooks before a human ever reviews a single line.
That implicit trust model is finally ending. Starting with npm 12 (expected in July 2026), GitHub is flipping the default from opt-out to opt-in. As a cloud and security architect who has spent the last several years building landing zones and policy-as-code guardrails, I think this is one of the most consequential supply chain changes in npm's history and it's arriving at exactly the moment a new class of attacker has learned to target it.``
What's actually changing in npm 12
preinstall,install, andpostinstallscripts from dependencies will no longer run automatically they require explicit approval vianpm approve-scripts.Native module builds via
node-gyp(commonly triggered through abinding.gypfile) are blocked by default unless explicitly allowed.Git dependencies and remote URL/HTTPS tarball dependencies will no longer resolve automatically you need
--allow-gitor--allow-remote.A new
min-release-agesetting lets teams block freshly published package versions until they've existed for a configurable window, closing the door on attacks that rely on rapid adoption before detection.
Teams on npm 11.16.0+ can run npm approve-scripts --allow-scripts-pending today to see exactly which dependencies in their tree currently run scripts, approve the ones they trust, and commit that allowlist to package.json before the breaking change lands.
This directly targets a pattern that has repeated for years â event-stream, ua-parser-js, colors/faker â but recently escalated sharply. A backdoored version of axios (400 million monthly downloads) shipped a cross-platform RAT that executed roughly one second into install, before dependency resolution even finished. The malicious version sat live for just over three hours before removal â plenty of time for mass compromise.
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes â full credit and traffic to the original publisher.