GitHub Added Manual 2FA Checkpoint for npm Packages

The opt-in staged publishing feature aims to prevent automated supply chain attacks by requiring human authentication.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration of a heavy steel vault-door mechanism with a single keyhole, symbolizing a digital security checkpoint.
GitHub has introduced a mandatory two-factor authentication checkpoint for new npm package releases to counter automated software supply chain attacks. AI Illustration. Upload story photo >

Live Poll

Should software registries mandate human approval for code updates to improve security?

GitHub released npm CLI version 11.15.0 on May 22, 2026, introducing a staged publishing feature that mandates manual 2FA for new releases. This security gate was implemented to address systemic vulnerabilities in the registry, which hosts over three million open-source packages.

Why it matters

The development attempts to break the automated pipeline used in mass supply chain attacks, where stolen CI/CD tokens previously allowed for the immediate seeding of malicious code. This security measure follows high-profile compromises, including the March 2026 theft of the axios library maintainer credentials.

Staged publishing routes tarballs to a queue that remains inaccessible until a maintainer performs interactive 2FA, distinguishing it from automated trusted publishing using OIDC (OpenID Connect) which cannot complete the final approval. The mechanism targets a registry landscape housing over 3 million packages.

The players

GitHub

A Microsoft-owned platform providing hosting for software development, version control, and the npm registry.

TeamPCP

An adversarial group responsible for executing supply chain attacks using poisoned packages and stolen CI/CD tokens.

The details

When a maintainer triggers the new staged workflow, the package tarball — a compressed archive format for distributing software code — is held in a secondary queue. Even if a CI/CD token is compromised, the malicious package cannot be published because the system prevents automated finalization, requiring a human to manually authenticate via 2FA. This addresses the specific vulnerability exposed by TeamPCP, which previously deployed over 500 poisoned packages across 20 coordinated attack waves.

Timeline

  1. March 2026: Maintainer account theft led to the compromise of the axios JavaScript library.

  2. May 22, 2026: GitHub released npm CLI 11.15.0 containing the new staged publishing feature.

  3. September 2026: A detailed report on the new security gates was published.

The Tech Race

This manual checkpoint follows the adoption of the OpenID Connect (OIDC) trusted publishing standard, which had previously streamlined uploads but lacked a human approval layer. By introducing this gate, GitHub is responding to the security parity challenges faced by other ecosystems like PyPI and Crates.io.

Package maintainers must upgrade to npm CLI version 11.15.0 and explicitly opt into the staged publishing feature to gain this protection. Organizations relying on npm dependencies should monitor for increased use of this workflow, as it introduces a manual step into the standard automated CI/CD deployment cycle.

The takeaway

The move toward human-in-the-loop authentication suggests that registries are moving away from purely automated trust models to mitigate credential theft. Maintainers should evaluate their release pipelines against this new checkpoint to ensure future deployments account for the required 2FA manual approval step.

Further reading

Learn more about securing software supply chains on our Cybersecurity hub.

More information

View the release details for this security feature in the Official GitHub Changelog.

Source note: This article includes information reported by GCN.

Live Poll

Should software registries mandate human approval for code updates to improve security?