A stolen token is only useful if it can publish without a human, so the registries' defenses target that step. Trusted publishing (npm 2,036 since July 2025, PyPI 2,431 since 2023, crates.io since 2025) replaces stored tokens with short-lived OpenID Connect credentials that a CI run obtains for one repository and workflow; there is nothing on disk to steal. Packages published that way can carry a provenance attestation, signed through Sigstore 69,885 , that links the tarball to the exact commit and workflow that built it (MERN Stack Development, Trusted Publishing sets it up). npm then tightened publishing through 2026 in response to the worms:
Staged publishing (npm CLI 11.15.0, May 2026): npm stage publish uploads a version to a queue, and it becomes installable only after a maintainer approves it with a 2FA challenge. It is opt-in per package.
Stage-only tokens (September 2026) let CI stage versions but not publish them, and npm plans to end direct publishing with 2FA-bypass tokens in January 2027.
As a consumer you can check what you received. npm audit signatures verifies the registry's signature on every installed tarball and any provenance attestations.
cd ~/v5-ch1/booknest && npm audit signaturesaudited 82 packages in 3s 82 packages have verified registry signatures 1 package has a verified attestation (use --json --include-attestations to view attestation details)
All 82 tarballs are exactly what npmjs signed, so no mirror or proxy tampered with them. Only proxy-addr came with provenance; Express 5.2.1 24,430 and pg 8.23.0 have none. Provenance also proves only where a package was built, not that its code is benign: a compromised repository builds malware with valid provenance.