GitHub is tightening npm publishing rules after a wormable malware attack exposed weaknesses in the open source supply chain. Recent npm Supply Chain AttacksIn September 2025, GitHub disclosed a serious incident involving the Shai-Hulud worm, a self-replicating malware that spread through compromised npm maintainer accounts. Attackers injected malicious post-install scripts into widely used JavaScript packages, enabling the worm to steal not only npm tokens but also a range of sensitive secrets. Advertisementnpm’s Roadmap for Security HardeningTo reduce the risk of token abuse and prevent future wormable attacks, GitHub has announced new rules for npm publishing. The lesson is clear: securing the software supply chain requires vigilance, collaboration, and proactive adoption of security best practices.