If you use Chrome, you're vulnerable until you install this update.
With npm v12, GitHub closes a central attack vector: installation scripts from dependencies will only run after explicit ...