A recent supply-chain attack on a widely used JavaScript developer account could have spread malicious code across the web, ...