Trusted publishing, besides eliminating the need for npm tokens, establishes cryptographic trust by authenticating each publish using short-lived, workflow-specific credentials that cannot be exfiltrated or reused. "Every package published via trusted publishing includes cryptographic proof of its source and build environment," GitHub noted back in late July 2025. Npm Package Includes QR Code-Based TechniqueThe disclosure comes as software supply chain security company Socket said it identified a malicious npm package named fezbox that's capable of harvesting browser passwords using a novel steganographic technique. But, in reality, it harbors stealthy code to fetch a QR code from a remote URL, parse the QR code, and execute the JavaScript payload contained within that URL. "However, the use of a QR code for further obfuscation is a creative twist by the threat actor.