Popular npm library ‘coa’ was hijacked today with malicious code injected into it, ephemerally impacting React pipelines around the world. ‘Coa’ is a command-line options parser for Node.js projects and is used by almost 5 million open source repositories on GitHub. Another popular npm component ‘rc’ was also found to have been hijacked, with malicious versions 1.9, 1.3.9 and 2.1.3. Malware identical to hacked ‘ua-parser-js’ and fake Noblox packages.”]