Hacking 20 high-profile dev accounts could compromise half of the NPM ecosystem

  • Are all the high profile accounts using multifactor auth? In a way that isn't tied to an SMS?