- Granular access tokens that could bypass 2FA can no longer perform sensitive account, organization, or package management actions.
- Sensitive actions now require an interactive 2FA challenge, enforcing two‑factor authentication.
- The change tightens security for npm token usage and may impact existing automation.