npm extends recovery-code security holds to all accounts
A 72-hour hold on publishing and token creation now follows any npm recovery-code sign-in, not just high-impact accounts.
npm now places a 72-hour security hold on any account after a successful sign-in with a recovery code, a protection that previously applied only to high-impact accounts. During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused, though signing in and browsing or installing packages still work. The hold lifts automatically, with no action or support request needed.
The change extends preventive protections GitHub had built for high-impact npm accounts to all accounts, aiming to slow account-takeover attempts and reduce the risk of malicious publishing from a compromised recovery code. Anyone unexpectedly blocked from publishing who didn't sign in with a recovery code is advised to contact npm Support.

