Attack post-mortem
shai-hulud: the npm worm that propagates through postinstall scripts
Self-replicating npm worms scrape publish tokens from infected developer machines and use them to publish malicious versions of every package those tokens can reach. Here is the propagation pattern, why it scales, and what reduces the blast radius.