After that I never used npm again.
Some security people are warning against Electron (at least on Linux):
https://github.com/secureblue/secureblue/issues/193#issuecom...
A recruiter profile disappeared from my inbox in linkedin after I sent a PR to a github project for a an interview so I got suspicious and checked if there was any unrecognized open connection usng `lsof -nPi | grep ESTABLISHED` and there was one, found the script, read it to see what it did - tried to steal crypto and browser credentials.
To be sure it did not install other stuff I could not find I did a full reinstall of the OS. Now I don't use npm ever again.
The vipers in the big nest need a bunch of trash cyber security media to premise renewal of sanctions against DPRK.
Bless our patriotic vipers, and their white hat hackers/influencers.