Several popular npm packages, including debug and chalk, were compromised with malicious code that intercepts crypto and web3 activity in the browser. The code was obfuscated and executed on the client-side, allowing attackers to manipulate wallet interactions and redirect funds. The packages were updated with the malicious code, which was not present in the source GitHub repository. The incident highlights the importance of package security and the need for developers to be cautious when updating dependencies.