Yet again a new supply chain attack
https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
Aaand it's very spicy
GitLab discovers widespread npm supply chain attack

Malware driving attack includes "dead man's switch" that can harm user data.

about.gitlab.com