Upwind was the first to publicly report that [email protected], a widely used npm package with 154 million weekly downloads, contained a malicious preinstall script that harvested AWS credentials, ...