Attackers compromised hundreds of npm packages by stealing credentials and using automated malicious preinstall scripts to inject malware. This incident highlights the need for organizations to isolate publishing workflows from dependency installation processes to prevent unauthorized code execution.