New npm supply-chain attack self-spreads to steal auth tokens