So there I was, first week at a new job, trying to get my local dev environment set up. Ran npm install on a perfectly normal project and immediately got slapped with this:
npm ERR! code UNABLE_TO_VERIFY_LEAF_SIGNATURE
npm ERR! errno UNABLE_TO_VERIFY_LEAF_SIGNATURE
npm ERR! network request to https://registry.npmjs.org/lodash failed, reason: unable to verify the first certificate
npm ERR! network This is a problem related to network connectivity.
My first instinct was to blame my machine. Spent a good 45 minutes reinstalling Node. Classic mistake. The actual culprit? The corporate proxy doing SSL inspection — basically a man-in-the-middle that decrypts and re-encrypts your HTTPS traffic using the company's own root certificate. Your OS might trust that cert. npm doesn't know it exists.
I've seen this trip up dozens of developers across different companies and it almost always looks the same. You switch jobs, join a new network, or IT quietly rolls out a new security policy and suddenly your entire JS toolchain is broken. Here's what's actually going on and how to fix it.
Why SSL inspection breaks npm
When your corporate proxy intercepts HTTPS traffic, it presents its own certificate instead of the real one from npmjs.org. This certificate is signed by your company's internal Certificate Authority (CA). Windows and macOS usually trust this because IT pushed the CA cert into the system certificate store via group policy. But Node.js — and by extension npm — ships with its own bundled CA list and doesn't automatically check the system store. So as far as npm is concerned, that intercepted certificate is from an untrusted source, and it bails.
It's actually a sensible security model in a vacuum. It just creates real friction in enterprise environments. And honestly, IT teams don't always think about developer tooling when they roll out SSL inspection. They're thinking about browsers.
Fix 1: Point npm at your corporate CA certificate
This is the cleanest fix and the one I'd recommend first. You need to grab your company's root CA certificate (usually a .pem or .crt file — ask your IT team, or you can export it from your browser) and tell npm to trust it.
Once you have the cert file, run:
npm config set cafile "C:\path\to\your\corporate-ca.pem"
On Mac or Linux:
npm config set cafile "/usr/local/share/ca-certificates/corporate-ca.pem"
You can verify it got set by running npm config get cafile. After this, npm will include your corporate CA when validating certificates and things should just work. No security shortcuts, no disabling anything important — you're doing it the right way.
One thing worth noting: if you have multiple CA certs to trust, you can concatenate them all into a single PEM file. Just open them in a text editor, paste one after the other, save it, and point cafile at that combined file.
Fix 2: Set the NODE_EXTRA_CA_CERTS environment variable
This one is handy because it works across npm, yarn, and anything else running on Node — not just npm. Instead of configuring npm directly, you're telling Node itself to trust additional certificates on top of its built-in list.
# On Windows (PowerShell)
$env:NODE_EXTRA_CA_CERTS = "C:\path\to\corporate-ca.pem"
# Or permanently via System Properties > Environment Variables
# On Mac/Linux (add this to your .bashrc or .zshrc)
export NODE_EXTRA_CA_CERTS="/usr/local/share/ca-certificates/corporate-ca.pem"
After setting it, open a fresh terminal and try npm install again. I actually prefer this method when I'm bouncing between tools — it's a one-and-done setting at the environment level rather than configuring each tool individually. Yarn, npx, custom Node scripts — they all pick it up automatically.
Fix 3: Configure npm to use your proxy explicitly
Sometimes the SSL error is compounded by npm not even routing through the proxy correctly in the first place. If your network requires explicit proxy settings (common in stricter corporate environments), npm might be trying to reach the internet directly and failing at the network layer before SSL even comes into play.
npm config set proxy http://your-proxy-server:8080
npm config set https-proxy http://your-proxy-server:8080
If your proxy requires authentication:
npm config set proxy http://username:password@your-proxy-server:8080
npm config set https-proxy http://username:password@your-proxy-server:8080
Ask your IT team for the proxy address — or check your browser's proxy settings, that's usually the same one. On Windows, it's under Settings > Network & Internet > Proxy. Combine this with Fix 1 or Fix 2 and you've got a pretty bulletproof setup for most corporate environments.
Fallback: the nuclear option (and why to avoid it in prod)
You've probably already seen this suggestion somewhere online:
npm config set strict-ssl false
Yes, it works. Yes, it will make the error go away immediately. But please don't leave it like this. Disabling SSL verification means npm won't check certificates at all — not your company's, not anyone's. You're now installing packages over a connection that could theoretically be tampered with by anyone on the network, not just your sanctioned corporate proxy. It's fine for a quick sanity check to confirm the SSL cert is the actual problem, but set it back to true right after:
npm config set strict-ssl true
In my experience, the reason people leave strict-ssl false permanently is because they got it working in a hurry and never revisited it. Don't be that person. Especially not in a CI/CD pipeline — I've seen that config committed into Docker images and it makes security teams very unhappy.
Alright, so to recap quickly: grab your corporate CA cert from IT, use cafile or NODE_EXTRA_CA_CERTS to tell Node about it, and make sure your proxy settings are configured if needed. That covers the vast majority of corporate proxy SSL inspection issues with npm.
Hope this saves you the 2-hour rabbit hole I fell into my first week. If you're setting up a new machine at a corporate job, honestly just make this part of your standard dev environment checklist — it'll come up eventually.
Related: How to Fix npm Error Code self_signed_cert_in_chain (Quick Fix)
๋๊ธ
๋๊ธ ์ฐ๊ธฐ