Supply chain attacks in npm: what audit doesn't detect | Juanchi.dev