From the presentation
From AiTM phishing to autonomous worms: a deep dive into 2025 npm attacks — Insomni'hack 2026.
Head to npmjs.com and sign in to get started.
0 / 0 completed
Section Account > Access tokens
For each active token:
Section Account > Two-Factor Authentication
Section Account > Linked Accounts & Recovery Option
Organization admin page
For each package:
After switching to Trusted Publishing: