The rate of npm supply chain attacks is so great that "the latest npm security incident" is ambigious after just a few hours...
This is now the latest attack:
The latest npm security incident has a slightly different shape but would still have been mitigated by what I suggested back in January.