That was my first thought. But then I realized some guy basically broke something so his stuff would work and someone else's wouldn't. He didn't destroy files, but that was malicious as hell.
more like dramaticious if you ask me... but also uncovers actual dangerous weaknesses in the npm delivery pipeline...