npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of the largest credential-based attack surfaces on the registry.
This only impacts npm granular access tokens. This does not affect GitHub personal access tokens, GitHub App tokens, or GITHUB_TOKEN in Actions.
What now requires an interactive 2FA challenge
Creating or deleting tokens
Changing package access, maintainers, or trusted publishing configuration










