TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8408

@thehackernews

The Hacker News

Views10,700Post view count
PostedFeb 1302/13/2026, 10:46 AM
Post content

Post content

npm killed long-lived tokens after the Sha1-Hulud attack, shifting to short-lived sessions and MFA by default. Security improved — but MFA phishing and optional publish protections still leave gaps. Console access can still mean package compromise. 🔗 Where the new model still fails → https://thehackernews.com/2026/02/npms-update-to-harden-their-supply.html