A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
The full picture and practical recipes for the ultra-fast 200ms, 1/10th cost, 100% type-safe 'System One' model~0.