JFrog says six malicious npm packages used hidden install-time execution, JSONKeeper fetches, and sandbox checks to enable remote access.
Jamf says the Rust-based PamStealer targets Apple Silicon Macs, steals browser, wallet, Keychain, and clipboard data, and persists.
A tutorial with examples of various access and display types can be seen at crotwell.github.io/seisplotjs. Also see the wiki. Install with npm i --save seisplotjs.