From zdnet.com
Three JavaScript packages have been removed from the npm portal on Thursday for containing malicious code.
According to advisories from the npm security team, the three JavaScript libraries opened shells on the computers of developers who imported the packages into their projects.