A major JavaScript security scare unfolded after malicious versions of a widely used package were briefly published to npm ...