The npm packages were available since July, have elaborately obfuscated malicious routines, and rely on a fake CAPTCHA to ...