When you receive packages from Microsoft/GitHub/NPM you're basically begging for malware. Not just PRISM; Microsoft literally brings people from the NSA to run GitHub/NPM. https://portswigger.net/daily-swig/aaron-portnoy-theres-no-silver-bullet-for-ransomware-or-supply-chain-attacks