https://www.stepsecurity.io/blog/supply-chain-security-alert...
https://semgrep.dev/blog/2025/security-alert-nx-compromised-...
Can I turn off those post install scripts globally?
Are there alternatives to npm that do a better job here?