On June 17, a North Korean state actor compromised a single forgotten npm contributor account and — in 88 minutes — poisoned 144 packages used by more than a million JavaScript developers building AI applications. The payload hunted for cryptocurrency wallet credentials and authentication tokens across Windows, macOS, and Linux alike. On the same day, security researchers disclosed a critical…