A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, ...