Evidence · DiggingBeagle record
npm install-time security and GAT bypass2fa deprecation
GitHub's first-party npm v12 general-availability announcement. It states that dependency lifecycle scripts, Git dependencies, and remote URL dependencies became opt-in by default in npm v12, materially reducing the default attack surface used by PhantomRaven.
- Published
- Jul 8, 2026
- Accessed
- Sep 21, 2026
- Publisher
- GitHub
Evidence record
GitHub's first-party npm v12 general-availability announcement. It states that dependency lifecycle scripts, Git dependencies, and remote URL dependencies became opt-in by default in npm v12, materially reducing the default attack surface used by PhantomRaven.
Claim-level citations (1)
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: npm v12, generally available on July 8, 2026, changed install-time defaults so dependency lifecycle scripts and remote URL dependencies are opt-in rather than automatically trusted, directly reducing the default execution path used by PhantomRaven.
Install-time security defaults are now on