On November 24, 2025, researchers identified a wave of backdoored npm packages that had been downloading a second JavaScript runtime during install. Not a shell script, not a compiled binary from a CDN. A whole other interpreter.

Source: [Dev.to](https://dev.to/madhavan_srajangupta_34c/the-npm-worm-that-brought-its-own-interpreter-4ck1)

Sponsored