Casey Ellis interviews Feroza Bukadégie from Socket about NPM v12’s new security defaults, which disable install scripts by default. They discuss how attackers rapidly adapted by moving payloads into package code or exploiting trusted GitHub Actions pipelines, as seen in recent malware campaigns. The episode also covers upcoming NPM token restrictions and advises teams to enforce hard failures for skipped scripts to prevent production errors.