npm Extends 72-Hour Recovery-Code Security Holds to All Accounts
npm has extended a 72-hour security hold following a successful recovery-code sign-in to all accounts, a protection previously limited to high-impact accounts. This measure pauses publishing and other security-sensitive writes, such as creating access tokens, for three days. The change aims to further deter account-takeover attempts and mitigate the risk of malicious publishing from compromised recovery codes. Full account access is automatically restored after the hold expires without requiring any manual intervention.
Security (1) ›
- All npm Accounts Now Subject to 72-Hour Security Hold
npm now applies a temporary 72-hour security hold on all accounts after a successful recovery-code sign-in. This measure, previously for high-impact accounts, pauses publishing and other security-sensitive writes to prevent account takeovers and malicious publishing from compromised recovery codes.
https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts
Related releases
- GitHub Copilot Deprecates MAI-Code-1-Flash Model GitHub Changelog ·
- GitHub's Xcode 27 Runner Image Now Uses macOS 27 GitHub Changelog ·
- CodeQL 2.27.0 Adds Linux ARM64 Support, New Rust Security Query, and Expanded Framework Coverage GitHub Changelog ·
- GitHub Copilot now offers enterprise-managed permissions for agent operations GitHub Changelog ·
- GitHub introduces rulesets to block PRs with exposed secrets from merging GitHub Changelog ·
- GitHub Advanced Security trial expands to more Enterprise Cloud customers GitHub Changelog ·