Self-spreading npm malware targets developers in new supply chain attack