A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...