it is really astonishing that npm has not even publicly acknowledged the potentially ongoing credential-stealing worm attack. what is going on in there
I'll also note that this is being framed as "supply chain security" when the actual problem is the combined set of capabilities of npm and github, both of which are the property of microsoft. this is a microsoft problem
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/jcoglan/statuses/115609873341660343 on your instance and quote it. (Note that quoting is not supported in Mastodon.)