npm extends recovery-code security holds to all accounts
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts.
During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused. You can still sign in as well as browse and install packages. The hold expires automatically — no action or support request is needed to restore full access.
This extension builds on the preventive account protection npm introduced for high-impact accounts, further slowing account-takeover attempts and reducing the risk of malicious publishing from a compromised recovery code.
If you’re unexpectedly blocked from publishing and you didn’t use your recovery code to sign in, contact npm Support right away.