event-stream npm compromise (2018)
A maintainer handed the popular event-stream npm package to a new contributor, who added code that stole bitcoin wallet keys. The package had about 8 million weekly downloads.
The malicious version was taken down and the package flagged, but the wallet-stealing code had already reached users.
Raised awareness of maintainer-takeover risk in open-source registries and led to stricter ownership policies.
Plugin marketplaces are the new npm: trust in a repository that can be hijacked or silently altered.
