
NPM strengthens safety with ephemeral tokens and OIDC, but the supply chain is still at risk
In December 2025, npm applied a profound change in its authentication system to reduce the risk of supply chain attacks: it revoked the so-called "classic tokens" and promoted ses…







