GitHub implements mandatory enhanced account verification in NPM

Due to the increasing cases of repository hijacking of large projects and the promotion of malicious code through the compromise of developers' accounts, GitHub is instituting widespread enhanced account verification. Mandatory two-factor authentication will be implemented separately for maintainers and administrators of the 500 most popular NPM packages at the beginning of next year.

From December 7, 2021, to January 4, 2022, there will be a transition for all maintainers authorized to publish NPM packages but not using two-factor authentication to enhanced account verification. Enhanced verification requires entering a one-time code sent to your email when attempting to log in to npmjs.com or performing an authenticated operation in the npm utility.

Enhanced verification does not replace but rather complements the previously available optional two-factor authentication, which requires confirmation using one-time passwords (TOTP). When two-factor authentication is enabled, enhanced verification via email is not applied. Starting February 1, 2022, the process of transitioning to mandatory two-factor authentication for the maintainers of the 100 most popular NPM packages with the highest number of dependencies will begin. After migrating the first hundred, the change will be extended to the 500 most popular NPM packages based on the number of dependencies.

In addition to the currently available two-factor authentication scheme based on applications for generating one-time passwords (Authy, Google Authenticator, FreeOTP, etc.), in April 2022, plans are in place to add support for hardware keys and biometric scanners that support the WebAuthn protocol, as well as the ability to register and manage various additional authentication factors.

It should be noted that according to a study conducted in 2020, only 9.27% of package maintainers use two-factor authentication to secure access, and in 13.37% of cases when registering new accounts, developers attempted to reuse compromised passwords found in known data breaches. During the assessment of password reliability, access was gained to 12% of accounts in NPM (13% of packages) due to the use of predictable and trivial passwords, such as '123456'. Among the problematic accounts were 4 user accounts from the Top 20 most popular packages, 13 accounts from packages that were downloaded over 50 million times per month, 40 from packages with over 10 million downloads each month, and 282 that had over 1 million downloads monthly. Given the loading of modules through dependency chains, the compromise of unreliable accounts could potentially affect up to 52% of all modules in NPM.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster