Distributing a self-replicating malicious code using NPM
Gajus Kuizinas

As a start, those concerned could shrinkwrap their packages to prevent any secondary dependencies from unknowingly creeping in. That’s not a fix, but is an interim solution.

