Malicious npm packages spoofing Gemini and popular JavaScript libraries deliver OtterCookie, targeting software developers