GitHub Added Manual 2FA Checkpoint for npm Packages
The opt-in staged publishing feature aims to prevent automated supply chain attacks by requiring human authentication.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Should software registries mandate human approval for code updates to improve security?
GitHub released npm CLI version 11.15.0 on May 22, 2026, introducing a staged publishing feature that mandates manual 2FA for new releases. This security gate was implemented to address systemic vulnerabilities in the registry, which hosts over three million open-source packages.
Why it matters
The development attempts to break the automated pipeline used in mass supply chain attacks, where stolen CI/CD tokens previously allowed for the immediate seeding of malicious code. This security measure follows high-profile compromises, including the March 2026 theft of the axios library maintainer credentials.
Staged publishing routes tarballs to a queue that remains inaccessible until a maintainer performs interactive 2FA, distinguishing it from automated trusted publishing using OIDC (OpenID Connect) which cannot complete the final approval. The mechanism targets a registry landscape housing over 3 million packages.
The players
GitHub
A Microsoft-owned platform providing hosting for software development, version control, and the npm registry.
TeamPCP
An adversarial group responsible for executing supply chain attacks using poisoned packages and stolen CI/CD tokens.
The details
When a maintainer triggers the new staged workflow, the package tarball — a compressed archive format for distributing software code — is held in a secondary queue. Even if a CI/CD token is compromised, the malicious package cannot be published because the system prevents automated finalization, requiring a human to manually authenticate via 2FA. This addresses the specific vulnerability exposed by TeamPCP, which previously deployed over 500 poisoned packages across 20 coordinated attack waves.
Timeline
March 2026: Maintainer account theft led to the compromise of the axios JavaScript library.
May 22, 2026: GitHub released npm CLI 11.15.0 containing the new staged publishing feature.
September 2026: A detailed report on the new security gates was published.
The Tech Race
This manual checkpoint follows the adoption of the OpenID Connect (OIDC) trusted publishing standard, which had previously streamlined uploads but lacked a human approval layer. By introducing this gate, GitHub is responding to the security parity challenges faced by other ecosystems like PyPI and Crates.io.
Package maintainers must upgrade to npm CLI version 11.15.0 and explicitly opt into the staged publishing feature to gain this protection. Organizations relying on npm dependencies should monitor for increased use of this workflow, as it introduces a manual step into the standard automated CI/CD deployment cycle.
The takeaway
The move toward human-in-the-loop authentication suggests that registries are moving away from purely automated trust models to mitigate credential theft. Maintainers should evaluate their release pipelines against this new checkpoint to ensure future deployments account for the required 2FA manual approval step.
Further reading
Learn more about securing software supply chains on our Cybersecurity hub.
More information
View the release details for this security feature in the Official GitHub Changelog.
Source note: This article includes information reported by GCN.
Live Poll
Should software registries mandate human approval for code updates to improve security?









