npm plans to require interactive human 2FA confirmation before any new package publishes starting January 2027. This would effectively end npm worms, but it will break the entire ecosystem's CI/CD automation overnight. Other volunteer-run registries won't follow, leaving them as the next target.