"No way to prevent this" say users of only package manager where this regularly happens
Red Hat Insights' JavaScript packages on NPM suffered a supply chain attack stealing AWS, GCP, Azure, Kubernetes, Vault, npm, and CircleCI credentials, self-propagating via npm tokens and bypass_2fa. The incident is the latest in a long pattern of such attacks on NPM, the package manager where they regularly occur.