“Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware | Snyk”
https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/
Feels like there's something fundamentally broken about npm. That we've put all of the web dev and node eggs in a single basket is definitely a bad idea as well