Oh no, not again a meditation on NPM supply chain attacks