The supply chain threat has been dubbed “Package Planting” by researchers from cloud security firm Aqua. “Up until recently, NPM allowed adding anyone as a maintainer of the package without notifying these users or getting their consent,” Aqua’s Yakir Kadkoda said in a report published Tuesday.