npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend ...