npm install failing behind corporate proxy SSL inspection (how to fix it)

npm install failing behind corporate proxy SSL inspection (how to fix it)

Photo by ANOOF C on Unsplash

So there I was, first week at a new job, trying to get my local dev environment set up. Ran npm install on a perfectly normal project and immediately got slapped with this:

npm ERR! code UNABLE_TO_VERIFY_LEAF_SIGNATURE
npm ERR! errno UNABLE_TO_VERIFY_LEAF_SIGNATURE
npm ERR! network request to https://registry.npmjs.org/lodash failed, reason: unable to verify the first certificate
npm ERR! network This is a problem related to network connectivity.

My first instinct was to blame my machine. Spent a good 45 minutes reinstalling Node. Classic mistake. The actual culprit? The corporate proxy doing SSL inspection — basically a man-in-the-middle that decrypts and re-encrypts your HTTPS traffic using the company's own root certificate. Your OS might trust that cert. npm doesn't know it exists.

I've seen this trip up dozens of developers across different companies and it almost always looks the same. You switch jobs, join a new network, or IT quietly rolls out a new security policy and suddenly your entire JS toolchain is broken. Here's what's actually going on and how to fix it.

Why SSL inspection breaks npm

When your corporate proxy intercepts HTTPS traffic, it presents its own certificate instead of the real one from npmjs.org. This certificate is signed by your company's internal Certificate Authority (CA). Windows and macOS usually trust this because IT pushed the CA cert into the system certificate store via group policy. But Node.js — and by extension npm — ships with its own bundled CA list and doesn't automatically check the system store. So as far as npm is concerned, that intercepted certificate is from an untrusted source, and it bails.

It's actually a sensible security model in a vacuum. It just creates real friction in enterprise environments. And honestly, IT teams don't always think about developer tooling when they roll out SSL inspection. They're thinking about browsers.

Fix 1: Point npm at your corporate CA certificate

This is the cleanest fix and the one I'd recommend first. You need to grab your company's root CA certificate (usually a .pem or .crt file — ask your IT team, or you can export it from your browser) and tell npm to trust it.

Once you have the cert file, run:

npm config set cafile "C:\path\to\your\corporate-ca.pem"

On Mac or Linux:

npm config set cafile "/usr/local/share/ca-certificates/corporate-ca.pem"

You can verify it got set by running npm config get cafile. After this, npm will include your corporate CA when validating certificates and things should just work. No security shortcuts, no disabling anything important — you're doing it the right way.

One thing worth noting: if you have multiple CA certs to trust, you can concatenate them all into a single PEM file. Just open them in a text editor, paste one after the other, save it, and point cafile at that combined file.

Fix 2: Set the NODE_EXTRA_CA_CERTS environment variable

This one is handy because it works across npm, yarn, and anything else running on Node — not just npm. Instead of configuring npm directly, you're telling Node itself to trust additional certificates on top of its built-in list.

# On Windows (PowerShell)
$env:NODE_EXTRA_CA_CERTS = "C:\path\to\corporate-ca.pem"

# Or permanently via System Properties > Environment Variables

# On Mac/Linux (add this to your .bashrc or .zshrc)
export NODE_EXTRA_CA_CERTS="/usr/local/share/ca-certificates/corporate-ca.pem"

After setting it, open a fresh terminal and try npm install again. I actually prefer this method when I'm bouncing between tools — it's a one-and-done setting at the environment level rather than configuring each tool individually. Yarn, npx, custom Node scripts — they all pick it up automatically.

Fix 3: Configure npm to use your proxy explicitly

Sometimes the SSL error is compounded by npm not even routing through the proxy correctly in the first place. If your network requires explicit proxy settings (common in stricter corporate environments), npm might be trying to reach the internet directly and failing at the network layer before SSL even comes into play.

npm config set proxy http://your-proxy-server:8080
npm config set https-proxy http://your-proxy-server:8080

If your proxy requires authentication:

npm config set proxy http://username:password@your-proxy-server:8080
npm config set https-proxy http://username:password@your-proxy-server:8080

Ask your IT team for the proxy address — or check your browser's proxy settings, that's usually the same one. On Windows, it's under Settings > Network & Internet > Proxy. Combine this with Fix 1 or Fix 2 and you've got a pretty bulletproof setup for most corporate environments.

Fallback: the nuclear option (and why to avoid it in prod)

You've probably already seen this suggestion somewhere online:

npm config set strict-ssl false

Yes, it works. Yes, it will make the error go away immediately. But please don't leave it like this. Disabling SSL verification means npm won't check certificates at all — not your company's, not anyone's. You're now installing packages over a connection that could theoretically be tampered with by anyone on the network, not just your sanctioned corporate proxy. It's fine for a quick sanity check to confirm the SSL cert is the actual problem, but set it back to true right after:

npm config set strict-ssl true

In my experience, the reason people leave strict-ssl false permanently is because they got it working in a hurry and never revisited it. Don't be that person. Especially not in a CI/CD pipeline — I've seen that config committed into Docker images and it makes security teams very unhappy.

Alright, so to recap quickly: grab your corporate CA cert from IT, use cafile or NODE_EXTRA_CA_CERTS to tell Node about it, and make sure your proxy settings are configured if needed. That covers the vast majority of corporate proxy SSL inspection issues with npm.

Hope this saves you the 2-hour rabbit hole I fell into my first week. If you're setting up a new machine at a corporate job, honestly just make this part of your standard dev environment checklist — it'll come up eventually.

Related: How to Fix npm Error Code self_signed_cert_in_chain (Quick Fix)

๋Œ“๊ธ€

Mojang Session Servers Down? Here's Why You Can't Log Into Minecraft Right Now

Photo by Patrik Kernstock on Unsplash So you sit down to play some Minecraft, probably after a long day, maybe you've got friends waiting in a server lobby, and you get smacked with this: Failed to connect to the server. Error: Authentication servers are down for maintenance. Or sometimes it shows up as: Failed to login: Invalid session (Try restarting your game and the launcher) Yeah. The Mojang session servers are down, or at least they're not talking to your game properly. I've seen this come up constantly in forums and Discord servers whenever there's a Mojang outage, and the frustrating part is — half the time people don't even realize it's not their fault. Here's what's actually going on. Why This Happens Minecraft doesn't just let you waltz into a multiplayer server. Every time you connect, your client reaches out to Mojang's session servers at session.minecraft.net to verify you...

what is art therapy AI painting checker Introducing the AI HTP Test Site: A New Era in Art Therapy

 #what is art therapy #art therapy activities   AI Art Above is the AI ​​picture psychological test. Below is the AI ​​HTP tree human house test.  Psychotherapy test AI Art Psychotherapy HTP test Introducing the AI HTP Test Site: A New Era in Art Therapy What Is HTP? HTP (House-Tree-Person) is a well-known projective drawing test commonly used in art therapy and psychological evaluation. Participants draw a house, a tree, and a person, and mental health professionals interpret these drawings to gain insights into the individual’s emotional state, personality traits, and underlying issues. AI Meets HTP Thanks to advancements in artificial intelligence, the HTP test has evolved. Our AI HTP Test Site allows you to upload your drawings and receive a detailed, automated analysis. The system evaluates various elements—line thickness, spatial arrangement, color usage, and more—to provide immediate, data-drive...

์ด ๋ธ”๋กœ๊ทธ ๊ฒ€์ƒ‰

Zoho Mail IMAP Not Working: Every Fix I've Actually Used

Quick Summary Zoho Mail IMAP stops working for the dumbest reasons - wrong port, 2FA blocking app passwords, or DNS that looks fine but isn't. I've fixed this across Outlook 2016, iPhones, Android, and Mac Mail, and the root cause is almost always one of four things. Here's the exact step-by-step with real menu paths so you're not clicking around for two hours like I was the first time. Photo by Juanjo Jaramillo on Unsplash It was a Monday morning. One of our sales guys walks up and says his Outlook stopped pulling emails from Zoho. Just stopped. Overnight. Nothing changed - or so he said. Checked his machine, checked the account settings, everything looked right on the surface. Port 993, SSL enabled, correct email address. And yet. Nothing. Here's the thing - Zoho Mail IMAP issues have this annoying pattern where the settings look correct but something underneath is broken. Could be an app password that got invalidated when someone toggled 2FA. Could be IMAP ac...
↑