- Sources: primary
- Summary: The GitHub changelog states npm applies a 72-hour security hold to every account that signs in with a recovery code. During the hold the account cannot publish packages or create tokens. The changelog describes the change as extending an existing hold to all accounts.
- Why it matters: Any npm account that signs in with a recovery code now loses publishing and token creation for 72 hours, so a maintainer recovering an account cannot ship during the window and an attacker holding a stolen recovery code cannot either.
send feedback on this story