npm security update: Attack campaign using stolen OAuth tokens

npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.