npm is extending a 72-hour security hold to every account after recovery-code sign-in. Sensitive operations are restricted to give the owner time to detect an account takeover.

Quick answer

QuestionAnswer
Trigger?An npm recovery code.
Duration?72 hours.
Goal?Slow the impact of a stolen code on packages.

A particularly powerful secret

A recovery code restores access when the normal second factor is lost. An attacker who also has the password may bypass a key or authenticator. On npm, a malicious release can then reach many downstream projects.

What changes for maintainers

Legitimate maintainers must anticipate the restriction. Keep two active factors, including a backup key, and avoid making urgent releases depend on one account. OIDC trusted publishing also reduces long-lived tokens.

Review the organization

Audit package owners, remove inactive accounts and store recovery codes separately from passwords. Document revocation and investigate every login alert immediately, even when no release appears.

Justified friction

Three days feels long, but an npm account is supply-chain infrastructure. The hold cannot protect an already stolen publishing token; it does make recovery-code abuse less immediate and creates another chance to regain control.