'The attack was carried out by using a pattern that is becoming more
and more popular; publishing a “useful” package
(electron-native-notify) to npm, waiting until it was in use by the
target, and then updating it to include a malicious payload.'
src