TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GBHackers

pnpm 11 Enables Default Release-Age Guard to Curb npm Supply Chain Attacks

Mayura Kathir · 1 day ago · Read original ↗

ATT&CK techniques detected

6 predictions
T1195.001Compromise Software Dependencies and Development Tools
98%
“pnpm 11 enables default release - age guard to curb npm supply chain attacks pnpm 11 has been released with a strong focus on reducing software supply chain risk, introducing security - first defaults that directly address modern package ecosystem threats. the most significant ch…”
T1195.001Compromise Software Dependencies and Development Tools
95%
“attacker compromises a maintainer account and uploads a backdoored version, pnpm users with default settings will not install that version immediately, giving maintainers and registries time to detect and remove it. blocking exotic subdependencies pnpm 11 also enables blockexotic…”
T1195.001Compromise Software Dependencies and Development Tools
94%
“, clearer policy : teams define which packages are allowed to build scripts. this makes it easier to enforce strict controls and reduce unintended code execution during installs. the release closely follows the discovery of the mini shai - hulud campaign, which compromised packag…”
T1587Develop Capabilities
88%
“attacker compromises a maintainer account and uploads a backdoored version, pnpm users with default settings will not install that version immediately, giving maintainers and registries time to detect and remove it. blocking exotic subdependencies pnpm 11 also enables blockexotic…”
T1587Develop Capabilities
76%
“pnpm 11 enables default release - age guard to curb npm supply chain attacks pnpm 11 has been released with a strong focus on reducing software supply chain risk, introducing security - first defaults that directly address modern package ecosystem threats. the most significant ch…”
T1587Develop Capabilities
31%
“, clearer policy : teams define which packages are allowed to build scripts. this makes it easier to enforce strict controls and reduce unintended code execution during installs. the release closely follows the discovery of the mini shai - hulud campaign, which compromised packag…”

Summary

pnpm 11 has been released with a strong focus on reducing software supply chain risk, introducing security-first defaults that directly address modern package ecosystem threats. The most significant change in pnpm 11 is the introduction of a default Minimum Release Age of 24 hours (1440 minutes). This means newly published package versions are not eligible […]

The post pnpm 11 Enables Default Release-Age Guard to Curb npm Supply Chain Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.