Supply chain worms keep compromising trusted npm packages by stealing maintainer credentials and letting automated pipelines spread malware before anyone notices. Standard defenses like MFA and version pinning help, but don’t fix the root cause. The attacks will keep coming until package managers make structural changes and the ecosystem agrees on who owns security.