August 16, 2026

Valid certificates, stolen accounts: how attackers broke npm's last trust signal

a man standing in front of a white board
Paymo / Unsplash

On May 19, 633 malicious npm package versions passed Sigstore provenance verification. They were cleared by the system because the attacker had generated valid signing certificates from a compromised maintainer account.Sigstore worked exactly as desi...