That Shai-Hulud npm worm has now reached 500 packages: https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages

Also, doesn't seem to run on Windows (via Step Security)