In a case like this, the package maintainer's account itself has been hacked, so I'm not sure if that would be meaningful.
The only solution would be to prevent all releases from being applied immediately.
The only solution would be to prevent all releases from being applied immediately.
No hardware keys, no new releases.
They have it implemented.
I created NPM account today and added passkey from my laptop and hardware key as secondary. As I have it configured it asked my for it while publishing my test package.
So the guy either had TOTP or just the pw.
Seems like should be easy to implement enforcement.