NPM developer qix's account compromise potentially puts user funds at risk by compromising library dependencies used by bitcoin wallets.
GitHub, which owns the npm registry for JavaScript packages, says it is tightening security in response to recent attacks.
The developers have fixed several vulnerabilities in the current version of the Chrome web browser. Attacks are already occurring.