A malicious npm package tied to a campaign some observers have called “Malware-Slop” has been detected copying files from ...