Node.js just got better enterprise security

Posted on Monday, October 9, 2017 by AUSTIN HARRIS, Global Sales

At Node.js Interactive North America, npm, Inc. announced new enterprise-grade security features for users of npm and the npm Registry: two-factor authentication for publishing packages and read-only authentication tokens.

With more than 550,000 packages for mobile, IoT, front end, back end and robotics, npm is the first software registry to provide two-factor authentication for publishers, making it even safer for the 8.8 million developers and hundreds of thousands of companies who download over three billion npm packages per week.

Key features


- Two-factor authentication (2FA): offers an additional layer of protection for developers, as a third party cannot gain access to their npm account by guessing or stealing their password; also provides assurance to all users of the Registry that packages they depend upon are only updated by their publishers.

- Read-only authentication tokens: can be used to read private npm code, but not to write changes to the code; can also be restricted to work from only specific IP addresses. Companies that run a Continuous Integration/Continuous Deployment (CI/CD) workflow gain an extra degree of security: even if their CI/CD tools' credentials are compromised, they cannot be used by third parties to access or alter their code.

'More developers and companies than ever before use npm to manage code for every type of project. There has never been an incident in which anyone exploited a vulnerability to steal user credentials, but our work to improve security is never done,' said Silverio. 'Developers and companies depend on us to add new, stronger barriers to protect the npm Registry and ensure the integrity of open source software so they can build amazing things.'

Two-factor authentication and read-only authentication tokens are the latest additions to npm's software features which also include on-premises and single-tenant private registries for enterprises; proactive analysis of the registry by security researchers to detect malicious packages; integration with the Node Security Platform to alert developers to known vulnerabilities; and security audits, code reviews, and penetration tests by ^Lift Security.

'Our team is extremely excited for the increased security that two-factor authentication and read-only tokens bring to developing with npm,' said Adam Baldwin, founder and team lead of ^Lift Security and founder of the Node Security Platform. 'Developers who choose to use 2FA get increased account security and set a precedence that they care about the integrity of their code. Using read-only tokens is a best practice for minimizing attack vectors and keeping private data secure.'

npm's two-factor authentication and read-only authentication tokens are available immediately to all developers who update their npm application. They will also be included in the Node.js Foundation's Long Term Support (LTS) distribution of Node.js v8.

'As large enterprises continue to invest in the Node.js ecosystem, security and stability remain two of their top priorities,' said Mark Hinkle, executive director of the Node.js Foundation. 'npm's encouraging work ensures the security and stability of the Node.js and JavaScript package ecosystem.'

More App Developer News

Tether QVAC SDK Powers AI Across Devices and Platforms



APAC 5G expansion to fuel 347B mobile market by 2030



How AI is causing app litter everywhere



The App Economy Is Thriving



NIKKE 3.5 anniversary update livestream coming soon



New AI tool targets early dementia detection



Jentic launch gives AI agents api access



Experts warn ai-generated health content risks misinterpretation without human oversight



Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines



AccuWeather Launches ChatGPT Integration for Live Weather Updates



Stop Using Business Jargon: 5 Ways Buzzwords Damage Job Performance



IT spending rises as banks balance legacy and innovation



Tech hiring slumps as Software Developer job postings fall



AI is becoming more widespread in collaboration tools



FCC prohibits new foreign router models citing critical infrastructure risks



ChatGPT Carbon Footprint Matches 1.3 Million Cars Report Finds



Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes



Accelerating corporate ai investment returns



Enviromates tech startup launches global participation platform



Private Repository Secures the AI-driven Development Boom



UK Fintech Platform Enviromates Connects Projects Brands and Consumers



Env Zero and CloudQuery Announce Merger



How Industrial AI Is Transforming Operations in 2026



AI generated work from managers is damaging trust among employees



Foresight Secures $25M to Bridge Infrastructure Execution Gap



Copyright © 2026 by Moonbeam

Address:
1855 S Ingram Mill Rd
STE# 201
Springfield, Mo 65804

Phone: 1-844-277-3386

Fax:417-429-2935

E-Mail: contact@appdevelopermagazine.com