Back to news

npm Locks Down Install Scripts; New Ransomware Gang Climbs Victim Charts

GitHub's npm overhaul targets supply chain exploits while a fast-rising ransomware group called The Gentlemen lures affiliates with a 90% revenue split.

npm Locks Down Install Scripts; New Ransomware Gang Climbs Victim Charts

What happened

GitHub has announced a significant change to npm version 12 that will disable install scripts by default — a direct response to supply chain attacks that exploit lifecycle hooks triggered during the 'npm install' command to execute malicious code. The move is classified as a breaking change, signaling a meaningful shift in how the world's largest package registry handles dependency installation. Separately, the ransomware collective known as The Gentlemen has climbed to the position of second most active ransomware group by victim count, built on an aggressive affiliate recruitment model that offers operators 90 percent of ransom proceeds. Security researchers at Krebs on Security have begun piecing together clues that may point to the real-world identity of the group's administrator.

Why it matters for your business

Any organization running JavaScript or Node.js workloads will need to audit build pipelines before upgrading to npm 12, since disabling install scripts by default could break legitimate automation that relies on lifecycle hooks. The upside is considerable: this change removes a well-documented attack vector that threat actors have used repeatedly to smuggle malicious payloads into development environments through seemingly trusted packages. On the ransomware front, The Gentlemen's high affiliate payout structure is designed to attract technically sophisticated criminals quickly, meaning the group's operational tempo is likely to accelerate. Security and operations leaders should treat the group as an active threat and confirm that endpoint detection, backup integrity, and incident response playbooks are current.

What to watch next

Expect package maintainers and DevOps teams to debate whether npm 12's new defaults strike the right balance between security and developer convenience, with potential workarounds that could reintroduce risk if adopted carelessly. On the threat actor side, researchers are continuing to map the infrastructure and persona trails left by The Gentlemen's administrator, and a public attribution could trigger law enforcement action or cause the group to rebrand — a pattern seen repeatedly with high-profile ransomware operations. Both stories underscore a broader theme heading into the second half of 2026: the software supply chain and ransomware-as-a-service economies are converging as priority risks for technology-dependent businesses.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp