For years, one stolen npm token was all an attacker needed to own a maintainer's account completely. Not just to publish a malicious package — but to create new tokens, add themselves as a maintainer, ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results