The npm account atool was compromised, resulting in 637 malicious versions across 317 packages being published in a 22-minute automated burst. The malicious payload harvests credentials, including npm tokens, GitHub PATs, AWS keys, and more, and exfiltrates stolen data through two parallel channels. The attack uses two execution paths and targets various platforms, including GitHub Actions, Jenkins, and Docker. The compromised packages include popular ones such as size-sensor, echarts-for-react, and @antv/scale.