Snyk disclosed a new npm worm that abuses binding.gyp to trigger node-gyp during package installation, allowing malicious packages to run code without lifecycle scripts. The worm steals credentials, persists access in GitHub, and self-propagates by infecting other maintainers in the npm ecosystem.