惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
U
Unit 42
罗磊的独立博客
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
aimingoo的专栏
aimingoo的专栏
Vercel News
Vercel News
N
Netflix TechBlog - Medium
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
小众软件
小众软件
博客园 - 【当耐特】
H
Help Net Security
The GitHub Blog
The GitHub Blog

Risky Business Media

Srsly Risky Biz: Trump's private hacker memo is the right idea Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras Risky Business #849 -- Trump will unleash contractors on cybercriminals Between Two Nerds: The eye of Sauron James Kettle on inventing new attack techniques with LLMs Risky Bulletin: The EU publishes its upcoming cybersecurity standards Sponsored: What npm 12 fixes… and what it doesn’t Risky Bulletin: US will let private companies carry out offensive cyber ops Soap Box: Zero Trust(ish) Networks Srsly Risky Biz: Data extortion is booming. Hooray! Risky Business #848 -- OpenAI comes clean Risky Bulletin: Russian hackers jump on the fake job interview train Between Two Nerds: The cyber resistance! Risky Bulletin: Two law firms pay giant ransoms Sponsored: Island's expansion to SASE and enterprise AI How private LLM inference actually works Risky Bulletin: A Meta AI model also escaped a testing sandbox Srsly Risky Biz: Being a North Korean hacker is about to be less fun Risky Business #847 -- Oops! Claude's accidental hacking spree Risky Bulletin: Hacker breaches Hungary's State Treasury Between Two Nerds: Hackers vs the state Risky Bulletin: Anthropic models also did the hacky-hacky Sponsored: The intrusion signals hiding in plain sight Risky Bulletin: Crime Stoppers puts bounty on INC ransomware group Srsly Risky Biz: Chipping away at Chinese AI risks Risky Bulletin: Cyberattack disrupts Minnesota water utilities Risky Business #846 -- OpenAI built a fireplace out of wood Benchmarks, borders and the true cost of AI regulation Between Two Nerds: Cyber is people Risky Bulletin: A JSON RCE bug is about to rock the Java world
Why NPM v12 won’t stop supply chain attacks
James Wilson · 2026-06-12 · via Risky Business Media

Risky Business Features Podcast

June 12, 2026

Presented by

James Wilson

James Wilson

Technology Editor

In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain attack mitigations coming in NPM v12.

NPM disabling (by default) auto-run install scripts and dynamic dependencies is a positive step forward… but it’ll take years for this new version to be adopted, and these changes do nothing to prevent malicious packages being imported into projects.

Further, Paul thinks disabling these features by default will introduce friction that will cause them to be re-enabled. When the choice is “this builds” and “this is less prone to malware”, the former will always win.

Your browser does not support the audio element.

Why NPM v12 won’t stop supply chain attacks

0:00 / 38:32

Logo