For years, one stolen npm token was all an attacker needed to own a maintainer's account completely. Not just to publish a malicious package — but to create new tokens, add themselves as a maintainer, ...