npm package targeted by a social-engineering supply-chain attack: the attacker gained the maintainer's trust by contributing pull requests and closing issues, then planted a back door that caused unsuspecting users to lose Bitcoins. Cited at wroclove.rb 2023 as a malware example in the OSS pollutants discussion.