Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRevoke the exposed credential first. If it is an npm access token, delete it in npm or revoke it with the npm CLI, then verify it is no longer active. If it belongs to GitHub, a cloud provider, a database, or another service, revoke it with that issuer instead. Removing a file or making a package private does not undo exposure.
1. Identify what was exposed and what it could access
Determine whether the secret is an npm access token or a credential issued by another service. Record where it appeared—for example, a package version, repository history, CI log, build artifact, or deployment configuration—and what permissions it had. An npm token can be revoked through npm; credentials from other providers must be revoked through those providers.
Do not paste the secret into a public issue, chat, or support report, and do not copy it into incident notes. Preserve non-secret details such as timestamps, affected package and version, repository or workflow location, and any activity you observed.
2. Revoke the credential
How to revoke a leaked npm token
Use whichever npm method is available to you. npm’s website guidance says to find the token under Access Tokens and delete it; some website revocations may take up to an hour. The npm CLI documentation says a revoked token is removed from the registry immediately and can no longer be used. Because the documented timing differs by method, verify the token is gone after revoking it.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
| Method | Procedure | Documented timing |
|---|---|---|
| npm website | Open npm’s Revoking access tokens guidance and delete the exposed token under Access Tokens. | Some revocations may take up to one hour, according to npm Docs. |
| npm CLI | Run npm token list, identify the exposed token’s ID, run npm token revoke <id|token>, then run npm token list again to verify removal. See the npm CLI v11 token reference. |
npm documents CLI revocation as immediate. |
Use the token ID shown by the CLI, not a shortened token value displayed for identification. If you cannot identify which token was exposed, or cannot access the account, use npm support for account-specific help. For a GitHub, cloud, database, or other credential, use that provider’s official revocation or rotation process.
3. Check for use and other copies
Revocation stops future use through that credential; it does not erase copies already downloaded, remove old logs, or reverse actions already taken. Review the places the credential could have reached and look for activity that falls within its permissions.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Check package versions and release outputs that may contain the secret.
- Review repository history, CI logs, build artifacts, and deployment configuration where it appeared or could have been copied.
- Inspect relevant npm account or provider activity for unexpected access, publishing, deployments, or configuration changes.
Scope this review to the credential’s actual reach. Exposure alone does not establish that someone used it or that the package was malicious.
4. Replace only the credentials the workflow needs
If a legitimate process still needs access, create a replacement credential with only the permissions required, update the intended consumer, and verify that workflow. For private npm dependency installation, npm recommends a read-only granular access token. Do not put a broad publishing token back into the repository, log, or artifact that exposed the original.
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
5. Contact npm or report malware when appropriate
For account-specific issues such as lost credentials or two-factor authentication problems, npm directs users to its support team through its support route. If you find malicious code in a package, follow npm’s malware reporting guidance. npm distinguishes malware reports from vulnerabilities in a package; it says vulnerabilities should be reported privately to the package maintainers. A credential appearing in a package is not, by itself, proof of malware.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Prevent another exposure
Review what the package includes
Check the files that are packed and published, then remove sensitive material from future package contents. npm specifically identifies private keys, passwords, personally identifiable information, and credit-card data as sensitive information to remove before publishing. Its guidance on creating and publishing private packages describes how .npmignore and .gitignore can help exclude unnecessary files. Ignore files do not protect secrets already committed, logged, or published.
Rank #4
Prefer trusted publishing where supported
npm’s trusted publishing guide describes using OpenID Connect (OIDC) from supported CI/CD workflows to publish without a long-lived npm write token. The current guide lists GitHub Actions on GitHub-hosted runners, GitLab CI/CD on GitLab.com shared runners, and CircleCI cloud. It specifies npm CLI 11.5.1 or later and Node.js 22.14.0 or later; check the guide for current requirements before configuring a workflow.
After trusted publishing works, npm recommends restricting traditional token publishing access. Private dependency installation may still need a read-only granular token. Do not remove existing credentials until you have verified the replacement workflow works.
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Secure sign-in separately from access tokens
npm describes a security key as its strongest supported two-factor authentication option and also supports authenticator apps that generate one-time passcodes. A hardware security key can strengthen account sign-in, but it does not revoke an already exposed access token; handle token revocation as a separate incident step. See npm’s threats and mitigations guidance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

