Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog: