A widely used JavaScript package used with hundreds of millions of downloads has been compromised in a new supply chain ...