soo @npmjs.com new scanners were unable to detect a preinstall script. socket.dev/blog/popular... you had one job.
Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default. gh.io/npm-publish-...