Microsoft, Huntress, and Intego this month detailed attacks that show the ongoing evolution of the highly popular compromise technique.
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.