On August 4, a compromised maintainer account turned a routine npm release into a self-propagating worm that tore through the JavaScript ecosystem in under an hour, poisoning hundreds of packages tied to more than two billion monthly installs. A single stolen GitHub credential was enough to reach deep into the dependency tree of half the JavaScript world before most teams even knew there was a fire. Around the same time, a remote monitoring platform used by managed service providers to administer other companies’ networks turned out to have not one but two authentication bypass flaws — the sec