A new npm worm discovered in 2025 has exposed how fragile modern software supply chains have become. The attack did not rely on zero-day exploits or complex vulnerabilities. Instead, it abused trusted developer tools, leaked credentials, and automated workflows to spread silently across the npm ecosystem. The incident highlights a growing security problem where convenience…