The fact
Malicious package was detected before massive adoption, but highlights persistent npm supply chain risks.
Developers advised to audit dependencies and use tools like keygate to prevent accidental secret leaks.
Click the link to read an article on the topic: