NPM is getting all the attacks and attention because it is the biggest. But there's nothing language specific to this class of attacks.
Tanstack infected a bunch of other packages; then resolving their issue doesn’t fix the widespread issue
I’m sort of reminded of how back in the day windows was swiss cheese and people kept saying “it is because they’re the biggest”, and then microsoft started caring about windows security and it improved enormously. When will microsoft start caring about npm security?