This is not a false alarm — your password being revoked basically means that I was able to obtain it by some of the means described in this note (though neither of those involve npm directly). Basically any other person with an internet access (including malicious players) can also do that. If you are still using that revoked password anywhere — change it everywhere. If your token/password was rev