The npm blog has been discontinued. Updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. This is an analysis of the event-stream incident of which many of you became aware earlier this week. The malicious code targeted developers at a company that had a very specific development environment setup: running the payload in any other environment has no effect. The code was designed to harvest account details and private keys from accounts having a balance of more than 100 Bitcoin or 1000 Bitcoin Cash.”]
Source: https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident

