npm is now a 150k-slot NFT farm; your next “npm install” mines tea.xyz for randos while you foot the AWS bill. Congrats, you’re the yield.
https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/