NPM packages have been compromised by a self-replicating worm known as Shai-Hulud: https://www.blackduck.com/blog/npm-m...ud-threat.html

Basically it gets credentials and then publishes infected packages as the authenticated (compromised) user.