New from the Socket Research Team: A malicious npm package disguised as an #Advcash integration triggers a reverse shell during payment success. Unlike many malicious packages that execute code during installation, this payload is delayed until runtime. socket.dev/blog/npm-pac... #JavaScript