github GitHub Changelog ·

npm Extends 72-Hour Recovery-Code Security Holds to All Accounts

securitygaengineer
security

npm has extended a 72-hour security hold following a successful recovery-code sign-in to all accounts, a protection previously limited to high-impact accounts. This measure pauses publishing and other security-sensitive writes, such as creating access tokens, for three days. The change aims to further deter account-takeover attempts and mitigate the risk of malicious publishing from compromised recovery codes. Full account access is automatically restored after the hold expires without requiring any manual intervention.

Security (1)
  • All npm Accounts Now Subject to 72-Hour Security Hold

    npm now applies a temporary 72-hour security hold on all accounts after a successful recovery-code sign-in. This measure, previously for high-impact accounts, pauses publishing and other security-sensitive writes to prevent account takeovers and malicious publishing from compromised recovery codes.

Read the original announcement →

https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts

Related releases