Six npm packages pull their command server addresses from an attacker's Ethereum wallet, and three of them were trusted libraries whose accounts got taken over.