“After GlassWorm showed how quickly a malicious package could self-replicate across npm, and the chalk/debug hijacking ...
A threat actor has published tens of thousands of malicious NPM packages that contain a self-replicating worm, security researchers warn.