Why Provenance Verification Alone Does Not Stop a Poisoned npm Maintainer Account

Why Provenance Verification Alone Does Not Stop a Poisoned npm Maintainer Account

Why Provenance Verification Alone Does Not Stop a Poisoned npm Maintainer Account

Provenance attestations prove where an npm package was built, not who was at the keyboard when it was published, which is why a hijacked maintainer account can still push credential-stealing releases through a fully verified pipeline.

npmsupply-chain-securityprovenanceci-cdcredential-theft