npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
Malicious Sicoob.Sdk stole PFX certificates and client IDs via NuGet downloads, enabling API impersonation and payment abuse risks.