---
answer: direct
beat: dev-practices
source: 1 article · updated: July 8, 2026
---

Does npm v12 stop supply-chain attacks entirely?

No. Cybernews reports security researchers call it "not enough": a compromised maintainer account can still publish malicious code as a trusted, signed release, and malicious logic hidden in a package's runtime code — triggered on import rather than install — passes through v12's defaults untouched.

Answered in

npm's Biggest Security Overhaul in 16 Years Is Here — Attackers Are Already Adapting

npm v12 blocks install scripts, Git dependencies, and remote sources by default. Researchers say attackers are already routing around it.

Crashtech Editorial July 8, 2026 Development Best Practices

Read the full analysis

Other questions this article answers

More development best practices questions

Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.