What changed
npm v12 remains generally available with dependency lifecycle scripts, Git dependencies and remote-URL dependencies changed from automatic behavior to explicit opt-in. GitHub has also restricted bypass-2FA granular access tokens, expanded trusted publishing and made malware scanning complete before staged packages can be approved. On September 18, GitHub added a new granular access-token permission: Read and write (stage only). Automation holding that token can upload and stage a package version for review but cannot publish it directly to the npm registry. This adds a least-privilege boundary between build automation and the final release decision. The previously reported malware-scanning caveat remains relevant: Aikido Security says four September 7 packages carrying the identical Shai-Hulud payload hash from May reached npm despite publish-time scanning, so staged review and restricted credentials remain complementary controls rather than proof that an artifact is clean.
Why it matters
Package publishing pipelines often give CI credentials powerful enough to turn a compromised workflow into an immediate public release. Stage-only tokens narrow that blast radius: automation can prepare the artifact, while a separate approval path retains publish authority. Combined with npm v12’s install-time restrictions, trusted publishing and scan-gated staging, npm is increasingly splitting package trust across multiple controls. The Shai-Hulud finding also shows why those layers matter: malware scanning can miss an artifact, so limiting who or what can publish remains valuable independently of detection quality.
npm v12 still makes install-time execution explicit
Dependency lifecycle scripts, implicit node-gyp builds, Git dependencies and remote-URL dependencies are opt-in under npm v12. Teams can prepare policies under late npm 11 releases before upgrading CI and developer machines.
Publishing authentication has moved toward shorter-lived and narrower trust
GitHub has restricted sensitive operations for bypass-2FA granular access tokens and supports multiple trusted-publishing configurations per package. The September 18 stage-only token goes further by letting automation write a staged version without granting it the authority to make that version public.
Stage-only tokens separate artifact creation from release authority
The new Read and write (stage only) granular permission is designed for automated workflows. A workflow can stage a package version for review, but publishing requires a different authority. That means a compromised staging job no longer needs to hold a credential that can immediately release a package.
The staged-publishing gate still waits for malware scanning
Since September 3, staged packages cannot be approved until npm's malware scan is complete. The new token scope complements that gate: one control limits what automation can do, while the other inserts scanning and review before release.
Aikido says an unchanged Shai-Hulud payload passed through the scanner
Aikido reports that four packages published on September 7 contained the same file hash seen in the May @AntV Shai-Hulud wave. GitHub/npm had not published a root-cause account at the time of the previous dossier update. The evidence does not show that npm's scanner is generally ineffective, but it demonstrates that scan completion is not a sufficient trust boundary on its own.