Tech article
npm extends recovery-code security holds to all accounts
Publisher description: npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts.
github | Sep 9, 2026 | Allison
Automated excerpt
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This extension builds on the preventive account protection npm introduced for high-impact accounts, further slowing account-takeover attempts and reducing the risk of malicious publishing from a compromised recovery code.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.