How npm install scripts can be weaponized: a real-world example | Heykuki News