How did simply opening this email in something like Gmail or a desktop client result in it being able to compromise NPM packages under your control?
I'm just curious - and as a word of warning to others so we can learn. I may be missing some details, I've read most of the comments on the page.