The npm Setting Nobody’s Talking About That Stops Supply Chain Attacks
The Keyv/Cacheable npm worm compromised over 350 packages by exploiting our trust in popular packages. The fix isn’t better detection—it’s a single line in .npmrc: min-release-age=30. This simple time delay blocks opportunistic supply-chain attacks because attackers can’t afford to wait weeks for their malware to spread. Add it now.