What does it do: Other users have done some good analysis of what these payloads actually do. I don't know what to say. #116 (comment) I don't know what to say. #116 (comment) I don't know what to say. #116 (comment) What can I do: By this time fixes are being deployed and npm has yanked the malicious version. Ensure that the developer(s) of the package you are using are aware of this post. If you