A security issue was discovered in the npm registry, allowing an attacker to publish new versions of any npm package without proper authorization. The vulnerability was reported and fixed on November 2. The issue existed for an unknown amount of time and may have been exploited maliciously. GitHub is taking steps to improve security, including requiring two-factor authentication for maintainers and admins of popular packages.