A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...