THREATOPS
THREAT OPSThreat News › The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

medelastic_securityPublished 2026-08-07

<p>npm's <code>min-release-age</code> setting tells npm to ignore any package version published less than a set number of days ago, keeping freshly compromised releases out of <code>npm install</code> during the window when they do the most damage. Getting the setting onto developer workstations is straightforward. Knowing when someone quietly deletes it is a different problem entirely, and log-ta

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/npm-cooldown-removal-detection-elastic-agent