The format of the news articles about these attacks is also always the same:
- "npm has billions of downloads"
- "thousands of malicious packages"
- suspicious lack of detail about how many downloads *these specific packages* had
- "who knows how many projects have been affected" (well, you can literally just look at the download count)
Like, these people have to know exactly what they're doing