Advertisement
SU
INFO
Supply Chain
npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks
npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.
Runtime Rebel Intel
4 min read·Jun 13, 2026

HIGH
Supply Chain
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.
Runtime Rebel Intel
4 min read·Apr 22, 2026